News: 1588987781

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Need some weekend reading? How about the source code for UK, Australia's coronavirus contact-tracing apps

(2020/05/09)


The NHSX, a technology group within the UK government's National Health Service, has released the source code for its Android and iOS COVID-19 coronavirus contact-tracing apps in an effort to allay privacy concerns and improve the code.

Developers who have examined [1]the blueprints have not been entirely mollified, and have called out several potential problems.

For example, the apps, which are supposed to be pro-privacy, [2]use Google Analytics and the Firebase Analytics framework, configured in a way to allow personalized web advertisements. Also, they generate [3]a private key that's not private because it gets created on a remote server rather than on the user's device. And they link to [4]insecure HTTP resources .

What's more, the Android app exhibits bugs that affect [5]OnePlus devices .

Upon startup, the apps request Bluetooth and push notification permissions and reach out to api.svc-covid19.nhs.uk with an activation code, a push notification token, and a portion of the user-entered postal code. And the server replies with a linkingId that gets stored in the user's app settings.

"You are given a persistent anonymous ID by the system and that's used to create a broadcast id," explained Professor Alan Woodward, of England's University of Surrey, in a phone interview with The Register . "When you're diagnosed as positive that gets sent up to the server. They have a single key that can unlock that and get your persistent identifier."

The server receives a history of interactions when a person chooses to report symptoms and that gets run through an algorithm to compute a risk score that's used to determine whether people who came in contact with the reporting person should be notified.

Apple-Google COVID-19 virus contact-tracing API to bar location-tracking access [6]READ MORE

The apps, currently being tested on the [7]Isle of Wight , are designed to listen for Bluetooth emissions from nearby devices also running the apps, be they Android or Apple. The idea is to record when people come close to each other so that when someone declares they have COVID-19, the folks they have encountered can be warned.

While the NHSX apps appear not to track user location, [8]consistent with NHSX representations , it's [9]claimed the Android version requests location permissions that are unnecessary and could be used after an update to track user location.

In an [10]analysis on Thursday, Reincubate, a UK-based developer tools software biz, said that the inclusion of the ACCESS_FINE_LOCATION in the Android app is necessary for using Bluetooth. The iOS version, the company says, does not request location permissions.

Overall, Reincubate considers the apps to be [11]relatively well-behaved , respecting platform rules and not storing sensitive data. The firm observes that they utilizes some clever workarounds to remain active and attentive for proximate devices – at the likely expense of battery life.

Other programmers – noting that, for the iOS version, [12]Bluetooth discovery may fail when two locked devices come in range – disagree, characterizing the workaround as a violation of Apple's rules.

iPhones and iPads [13]clamp down on applications that use Bluetooth while running in the background. To get around the limitations, the UK government's software uses various tricks, such as a timer to [14]emit Bluetooth signals every few seconds, and listen for responses. This maintains [15]ping-pong like communications between nearby devices, keeping the tracing software alert.

However, there are some worst-case scenarios in which the iOS app [16]may stop working as expected and miss nearby devices, which is not great for a contact-tracing program.

Apple and Google, meanwhile, developed a framework for " [17]Privacy Preserving Contact Tracing ," an effort to accommodate government demand for better health data to deal with the coronavirus outbreak; neither tech giant wants to stand in the way of nationally backed projects, and both would prefer that contact tracing apps conform to an acceptable standard.

The Apple-Google API is designed to support background scanning of nearby devices in a more battery efficient manner, via the operating system, rather than periodically waking up apps. The framework is also decentralized to prevent tracking and identification of users and those they've come in contact with. Any data is shared with healthcare providers' databases; Apple and Google see none of it.

The NHSX apps do not use the Apple-Google framework, though the UK government is said to be mulling tapping the API.

There are at least 60 such contact-tracing app projects underway, some backed at a national level, others driven by interested organizations, in countries around the world. Some use centralized models others use decentralized ones; some are compulsory and others are voluntary.

Australia's contact tracing app, COVIDsafe – the [18]source code of which was also shared this week – has come under fire from independent software engineer Geoffrey Huntley for failing to address privacy problems brought to the attention of the app's developers. A recent update, 1.0.16, did not address most of the issues raised.

Problems include not refreshing the UniqueID to prevent tracking, the app stores details about the messages it sends and receives in unencrypted form, inconsistencies between app behavior and the app's privacy policy, and general lack of customer support, among other issued details at [19]covidsafe.watch .

Australia is also [20]shifting its app to the Apple-Google API after failing to work around the background Bluetooth limitations in iOS.

"Because these apps are being introduced so rapidly and there's not a lot of modesty on the part of developers or protection on the part of policy makers, there's a huge potential for this to go wrong," said Askan Soltani, an independent researcher and technologist who has served as Chief Technology Officer in the White House Office of Science and Technology Policy and Chief Technologist at America's consumer watchdog, the FTC.

Soltani said that while we need ways to expand COVID-19 testing capacity and to augment limited human-driven contact tracing, the potential consequences of these apps are not yet known. He said he had identified at least one attack on the Apple-Google platform that would also affect the UK apps. The attack involves a malicious actor generating a cascade of notifications on people's phones after intercepting tokens grabbed from network traffic at clinics.

For these apps to be effective, mass uptake is critical. Soltani said that smartphone penetration in the US is about 81 per cent which means you could achieve about 65 per cent efficiency. That's if everyone in the country installed and used a contact tracing app, "which we know won't be the case," he said.

False negatives and false positives are also a problem. Solatani said he was aware of people complaining that such apps don't work reliably due to platform limitations (which the Apple-Google framework aims to address).

Prof Woodward said that while there's been an active discussion about whether a decentralized model for the would be better, there's a more fundamental problem.

"Who is the customer for this and what did they ask for?" he said. "When it comes to data protection, I prefer to collect the least amount of information necessary. Is this about proximity alerts or getting extra information? The technologists have been asked to build a system in a certain way and it's likely there's no body in the loop saying, 'You don't really need this.'" ®

Sponsored: [21]Choosing A Low-Code Vendor



[1] https://github.com/nhsx

[2] https://github.com/nhsx/COVID-19-app-iOS-BETA/issues/11

[3] https://github.com/nhsx/COVID-19-app-Android-BETA/issues/14

[4] https://github.com/timb-machine/nhsx-contact-tracing-app/issues/20

[5] https://github.com/nhsx/COVID-19-app-Android-BETA/issues/9

[6] https://www.theregister.co.uk/2020/05/05/apple_googles_exposurenotification_api_update/

[7] https://covid19.nhs.uk/isle-of-wight.html

[8] https://www.ncsc.gov.uk/blog-post/security-behind-nhs-contact-tracing-app

[9] https://github.com/nhsx/COVID-19-app-Android-BETA/issues/16

[10] https://reincubate.com/blog/nhs-covid-19-background-tracing-details/

[11] https://reincubate.com/blog/staying-alive-covid-19-background-tracing/

[12] https://github.com/nhsx/COVID-19-app-iOS-BETA/issues/2

[13] https://www.theregister.co.uk/2020/05/05/uk_coronavirus_app/

[14] https://github.com/nhsx/COVID-19-app-iOS-BETA/blob/master/Sonar/Bluetooth/BTLEListener.swift#L43

[15] https://github.com/nhsx/COVID-19-app-iOS-BETA/issues/2#issuecomment-625547895

[16] https://github.com/nhsx/COVID-19-app-iOS-BETA/issues/2#issuecomment-625776753

[17] https://www.apple.com/covid19/contacttracing

[18] https://github.com/AU-COVIDSafe

[19] https://covidsafe.watch/

[20] https://www.theregister.co.uk/2020/05/07/covidsafe_australia_contact_tracing_app_issues/

[21] https://go.theregister.co.uk/tl/1936/-8579/choosing-a-low-code-vendor?td=wptl1936

Australian Gov legal team can not read it seems

john.jones.name

honestly I dont think Australian government legal team have a clue what they are doing...

They released the source code and although they copied from the opentrace repo (Singapore gov funded) which is under GNU General Public License v3.0

(Section 2 of GPL says that modified versions you distribute must be licensed to all third parties under the GPL.)

The Australian gov dept tried to license it under a new license and claim copyright... which is not how this works...

Incompetent legal dept would be a nice way of putting it...

I also love that they "archived" the github versions... no issues can be filed...

In a Australian gov public hearing the dept also refused to acknowledge that AWS could be (and very likely already is on regular basis) forced to hand over data based on United states courts (United States Foreign Intelligence Surveillance Court FISC, also called the FISA Court) the Australian Attorney General office cited that the advice was confidential (again rather petty and silly).

The only way they can turn this around is to pivot to using the Apple/Google decentralised model and say the app was a placeholder, trying things out... wipe most of the current data in the store and start distributing the list of tested confirmed codes that people can check securely on the phone uploaded by the health Dept after they confirm things with the individual via a medical diagnostic test (which is open to anyone now).

hell to really right their wrongs the best way would to host the data on secure Australian servers by an Australian company or Gov Dept.

The first thing we do, ...

Anonymous Coward

1) Is all the source code there? Is it possible to build the App from this source or is some code missing?

2) Are there any dependencies on 3rd Party libraries doing nefarious things whose source is not provided?

3) Is the App built from the provided source an exact binary match of what is being downloaded?

4) Repeat all of the above when a new version arrives or tries to update itself in place.

... and that's just the Client side.

The world's most avid baseball fan (an Aggie) had arrived at the
stadium for the first game of the World Series only to realize he had left
his ticket at home. Not wanting to miss any of the first inning, he went
to the ticket booth and got in a long line for another seat. After an hour's
wait he was just a few feet from the booth when a voice called out, "Hey,
Dave!" The Aggie looked up, stepped out of line and tried to find the owner
of the voice -- with no success. Then he realized he had lost his place in
line and had to wait all over again. When the fan finally bought his ticket,
he was thirsty, so he went to buy a drink. The line at the concession stand
was long, too, but since the game hadn't started he decided to wait. Just as
he got to the window, a voice called out, "Hey, Dave!" Again the Aggie tried
to find the voice -- but no luck. He was very upset as he got back in line
for his drink. Finally the fan went to his seat, eager for the game to begin.
As he waited for the pitch, he heard the voice calling, "Hey Dave!" once more.
Furious, he stood up and yelled at the top of his lungs, "My name isn't Dave!"