Australian contact-tracing app sent no data to contact-tracers for at least ten days after hurried launch
- Reference: 1588831326
- News link: https://www.theregister.co.uk/2020/05/07/covidsafe_australia_contact_tracing_app_issues/
- Source link:
Meanwhile, security researchers have alleged the app has serious flaws – one of which can broadcast the names of devices running the app – and one has criticised Australia’s government for not offering a formal method to point out such problems.
News that data is not yet flowing emerged yesterday at a hearing of Australia’s COVID-19 select committee at which officials from Australia’s Digital Transformation Agency, Attorney-General’s Department and Department of Health gave testimony. The [1]transcript [PDF] of the meeting reveals:
Agreements between Australia’s Federal and State governments to share COVIDSafe data are not yet in place. As States run health services and employ contact-tracers, this means no data gathered by the federally-administered app has been shared in the 10 days since its launch. Officials said they expect those arrangements will be in place “certainly this week”. Officials "are taking the extra steps of making sure we consult with privacy agencies" to ensure the data flows properly. Officials added that the backend of the app is working perfectly so data should flow once agreements are ironed out. State governments, meanwhile, have said their contact-tracing teams are yet to be trained to use data produced by the app.
Anticipated [2]problems with iPhones have materialised, as “quality of the Bluetooth connectivity for phones that have the app installed running in the foreground is very good, and it progressively deteriorates and the quality of the connection is not as good as you get to a point where the phone is locked and the app is running in the background.”
Australia is “aware of the performance issues as the app moves further into the background and are working with Apple and Google on the improvements that they're making to Bluetooth, and we will be one of the first adopters of that improved Bluetooth connectivity.”
Officials said the app was developed despite its creators and government knowing in advance it would be imperfect. “Our option was to wait until every feature was running perfectly and deliver a solution in six or 12 months time” the Committee was told.
Legal advice has been sought regarding the impact of the USA’s CLOUD Act on data collected by COVIDSafe, as it is stored in AWS. Officials would not release that advice and said they believe it is “not conceivable” the data could be accessed by US authorities, emphasised that security had been considered from every angle and opined that US courts would not likely look favorably upon a request to access data gathered by the app.
Government agencies have “limited” capacity to engage with developers who share opinions on the app, but are “are engaging with the tech community on general issues that they may be identifying and we're working through those in a methodical way. We have a backlog, as you would expect, of issues. We prioritise those and we deliver improvements on an iterative basis.”
A partial release of the app's source code is planned for late this week or early next week.
Serious flaws, no bug bounty, no evidence of engagement
Security researchers, meanwhile, continue to find problems with the app.
Geoffrey Huntley, a security researcher who with colleagues and acquaintances has decompiled the app’s Android .APK and observed the iOS app running with a debugger, told The Register he has found a flaw in the app’s use of unique identifiers that retains one value instead of making a change every two hours. He also said the app’s Bluetooth implementation makes it possible to read device names with a Bluetooth beacon.
Huntley also labelled the lack of a bug bounty program for the app “unusual” and said only personal relationships with government staff afforded him a channel through which to report his findings – after mailing government agencies' public email addresses with details of bugs and not receiving replies for a week.
Australia’s app uses some of Singapore’s open source contact-tracing code. Huntley said he found flaws in Singapore’s code, reported it to developers there and saw changes made on the same day. He said he’s since informed Australian authorities of the same problem and seen it left in place in an app update that he said has changed nothing of substance. His research and opinions are detailed in this Tweet and subsequent thread.
Issue 1 (which is a privacy breach) in [3]@jim_mussared 's research was confirmed by the Singapore team. It was fixed same day. It has not been fixed in the Australian app.
Nb. I also disclosed see above tweets about being ignored. [4]pic.twitter.com/wtGsy8Ki5R — geoffrey huntley (@GeoffreyHuntley) [5]May 6, 2020
Huntley has called upon those responsible for the app to implement formal customer service and developer community engagement tools, as he feels the app is a worthy weapon in Australia’s coronavirus response. However he has withdrawn his personal support for the app until the privacy issues he has identified are addressed.
Australia’s government, meanwhile, continues to tie increased adoption of the app to future lightening of social distancing regulations. Over five million Australians have downloaded the app at the time of writing, however with iPhones the majority of the national phone fleet COVIDSafe’s efficacy is currently questionable. ®
Sponsored: [6]Forrester Build a Digital Experience Portfolio
[1] https://parlinfo.aph.gov.au/parlInfo/download/committees/commsen/21693643-a9ab-41e2-8440-77267c6c7b37/toc_pdf/Senate%20Select%20Committee%20on%20COVID-19_2020_05_06_7691.pdf;fileType=application%2Fpdf#search=%22committees/commsen/21693643-a9ab-41e2-8440-77267c6c7b37/0000%22
[2] https://www.theregister.co.uk/2020/05/05/uk_coronavirus_app/
[3] https://twitter.com/jim_mussared?ref_src=twsrc%5Etfw
[4] https://t.co/wtGsy8Ki5R
[5] https://twitter.com/GeoffreyHuntley/status/1258178924451749888?ref_src=twsrc%5Etfw
[6] https://go.theregister.co.uk/tl/1936/-8554/forrester-build-a-digital-experience-portfolio?td=wptl1936
Re: You know they are bullshitting you when they say:
They had better be publishin the source code pretty soon as well. The original code they copied is published under GPL V3. Not even governments are allowed to break contracts.
Putting the Cart before the Horse
I recently read that the UK was planning a similar tracing app. They completed the Legal Agreements, Data Privacy Provisions, and published the Source Code before the sign off to go live. Seems like the Australian Government have not thought this through. I will not be downloading this App until the Source Code is Published and the Data Privacy Provisions are legislated as the Minister has proven that he cannot be trusted after the RoboDebt scandal.
Re: Putting the Cart before the Horse
Don't believe everything you read about the UK!
Re: Putting the Cart before the Horse
You can read about the UK's app right here on El Reg - https://www.theregister.co.uk/2020/05/05/uk_coronavirus_app/
In summary, it's full of security holes, is not in any way anonymised (despite lies from those involved claiming otherwise), and is run by the usual old boys' network of Tory associates including some of those involved with Cambridge Analytica and the Leave campaign. But probably most importantly of all, it is fundamentally incapable of actually functioning on both iOS and Android because neither OS actually allows bluetooth to be used the way the app needs.
It's certainly possible the UK government has been more competent than the Australian one here, but only in the sense that they've been better at generating kickbacks for their mates.
We have a betterr plan
The virus will miraculously disappear. No need for contact tracing apps here.
I will absolutely never download their knocked up over the weekend crap, despite Scotty's pleas.
I fear that a lot of the lemmings rushing to download it have no idea of the implications for their privacy and security.
Spare phone
I wont load it on my phone but I will dig out a spare phone , clean it thoroughly and then run it on that.
That way it may save lives (mine FFS) and with luck bankrupt the buggers hoping to make money off my info,
@The Central Scrutinizer
You can't be as smug as TouchPhone users. We can't even run the stupid app until the SourceCode is published. Hopefully we can roll in the Sinpore fixes before compiling and packaging.
Re: @The Central Scrutinizer
Rots o' ruck.
Apparently the UK NHS app is using the same centralised approach that, apart from the privacy concerns, relies on iPhone users bringing the app to the foreground periodically to ensure it keeps Bluetooth on.
https://www.theguardian.com/world/2020/may/06/critical-mass-of-android-users-needed-for-success-of-nhs-coronavirus-contact-tracing-app
Though this article seems to suggest the Aussies are working with Apple to address this.
But this also shows we don't have a unified approach across the whole globe.
I am sure Australia will get as far as the UK does in 'working with apple'
https://9to5mac.com/2020/05/06/uk-nhs-contact-tracing-app/
or the french
https://9to5mac.com/2020/05/05/france-issues-misleading-statement/
IE not very far
Australia 2.0
The new Penal Colony.
Re: Australia 2.0
You clearly missed the 2.1 update, dude.
It also highlighted that Australia Government doesn't have control over National Data Soverienty
There's some political noise about security of the data which made people aware of the US Cloud Act.
COVIDSafe uses AWS cloud technology which means it automatically comes under the US Cloud Act. To get around this problem they has placed in special biosecurity provisions. Interesting, what about all the rest of data belong to the Australian government and businesses?
The US Cloud Act means that the US Federal Government can get access to any data stored on any US Cloud provider in any country.
The first of the bullet points brought to mind the saying that to fail to plan is to plan to fail. That was misleading. The rest made it clear that they'd knowingly planned to fail.
The only possible explanation for this is the politicians syllogism: something must be done, this is something therefore it must be done.
Vulnerabilities? What vulnerabilities?
So walking around, keeping 1.5m from everyone, with your Bluetooth on is safe? A quick delve into your favourite search engine will show you that it isn't. Googleing for 'bluetooth android vulnerability 2020' brought up a mere 1 million+ hits (I didn't worry about iPhones; they've got their own CovidSafe problems).
While you're here, can someone explain how this works?
1. According to their blurb, When the app recognises another user, it notes the date, time, distance and duration of the contact and the other user’s reference code . AFAIK, BT works through walls. I was unaware that viruses could travel through them though. Anyone for a host of false positives?
2. I found the statement by our PM to be rather disingenuous when he stated early on that the data would be held in Oz, hence giving all true blue Aussies a warm fuzzy feeling. He failed (at that time) to state that it was with AWS, a decidedly US company. As has been stated earlier, the US TLAgencies can grab anything they want without much hindrance from a company with US roots. Our beloved pollies also stated that not even a court order could get the data released to our gummint, but as a member of Five Eyes, Shirley they can get it (CLOUD Act), and hand it back to Peter Dutton, MP (Minister for keeping us safe from overseas nasties) without having to bother with any legalities.
Of course they'd never stoop to such things would they?.
You know they are bullshitting you when they say:
"Legal advice has been sought regarding the impact of the USA’s CLOUD Act on data collected by COVIDSafe, as it is stored in AWS. Officials would not release that advice and said they believe it is “not conceivable” the data could be accessed by US authorities, emphasised that security had been considered from every angle and opined that US courts would not likely look favourably upon a request to access data gathered by the app."