News: 1589482028

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

NHS contact tracing app isn't really anonymous, is riddled with bugs, and is open to abuse. Good thing we're not in the middle of a pandemic, eh?

(2020/05/14)


Analysis The current wisdom states that the sole path from COVID-19 lockdown involves vigorous testing of the population to identify new cases, paired with contact-tracing to limit the spread of infections. Smartphones make that easier, and the UK's National Health Service, like many other national governments, is working on an app to make it simpler.

But the implementation and design of this app (created by the NHS's digital arm, NHSX, in [1]conjunction with VMWare Inc and Zuhlke Engineering ) has raised concerns about privacy and efficacy, culminating with allegations that users are not actually anonymous.

Anonymity has a very precise definition under the prevailing legislation, including the European General Data Protection Regulations, and it’s unclear whether the current implementation meets that standard. This is due to the app’s practice of pinpointing phones with specific identifiers.

[2]Recital 30 of Europe's GDPR states that: “Natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols."

It provides a few examples, including IP addresses, cookie identifiers, and RFID tags. The concern is that these identifiers — which are linked to actual people in a one-to-one relationship — can be used to create profiles of the individuals they belong to.

By contrast, the approach taken by Google and Apple, sees phones generate completely distinct and random identifiers for each interaction. The random nature of these identifiers makes it more difficult to profile an individual from a key. Moreover, since only 14 days’ worth of keys are retained, it’s harder to trace the movements of an individual beyond the limits of what would be considered necessary for effective containment of COVID-19.

It's worth mentioning the head of NHSX has previously suggested user data [3]could be kept indefinitely for further research.

Another concern, raised by data protection expert Chris Pounder weeks ago, is that "because the UK has Brexit, powers in the European Withdrawal Act 2018 could be used to modify any UK_GDPR provision without recourse to Parliamentary scrutiny."

He added, in a fascinating look at the implications last week, that it "could be tempting (e.g. to reduce the pressures on the public purse) for government to enact legislation that makes certain processing of personal data compulsory. For instance, to prove entitlement to a COVID related benefit, there is a requirement to show that you have downloaded the APP and have received the COVID warning message."

Self-reporting

Another curiosity in the NHS's contact-tracing app is the decision to allow users to self-report their symptoms without a formal diagnosis. While this could potentially shorten the amount of time it takes to warn those who may have had contact with a sufferer, it also presents the very real possibility of abuse. False reports could see individuals self-isolate when they don’t need to, thereby placing an extra burden on the already-strained NHS capacity for testing.

Just yesterday, as revealed by [4]Wired , secret NHS plans to that effect were left hanging in the open via public Google Drive links. The leaked slides also referred to a COVID-19 "status feature" potentially to be pulled into a later version of the app, listing five options: "quarantine, self-isolating, social distancing, shielding and none" – which would also be selected by the user themselves.

Fancy some post-weekend reading? How's this for a potboiler: The source code for UK, Australia's coronavirus contact-tracing apps [5]READ MORE

This is in stark contrast to Germany’s application, called Corona Warn App, which [6]relies on confirmed medical tests to send warnings. The implementation here will see users scan a QR code provided by their physician, or otherwise manually type in a verification code, which links their account to their test results.

It doesn’t help that the NHS app, which was [7]tested in the Isle of Wight earlier this month, suffers from endemic operational woes. The Github issue tracker for the NHS [8]iOS and [9]Android contact tracing app is particularly damning.

In some cases, iPhones are unable to exchange handshakes with other iPhones when the app is running in the background. Meanwhile, on some Android phones, the Bluetooth functionality required for the app to work fails when it has [10]been exposed to too many connections. The NHSX has also identified problems with [11]iPhones connecting to Android devices.

With a formal release expected in the coming weeks, NHSX is under pressure to resolve these issues quickly, and ensure the final product works properly. Lives could depend on it.

But the question remains: can it be fixed? Or is the app so grotesquely riddled with design flaws, it's simply not fixable in a way that guarantees user privacy while performing its critical task? ®

Sponsored: [12]How To Accelerate Brilliant Digital Experiences With Low-Code



[1] https://www.theregister.co.uk/2020/05/12/vmware_tannzu_nhs_app/

[2] https://www.privacy-regulation.eu/en/recital-30-GDPR.htm

[3] https://www.theregister.co.uk/2020/05/04/uk_covid_app_human_rights_parliament/

[4] https://www.wired.co.uk/article/nhs-covid-19-app-health-status-future

[5] https://www.theregister.co.uk/2020/05/09/coronavirus_tracing_app_source_code/

[6] https://github.com/corona-warn-app/cwa-documentation/blob/master/translations/scoping_document.de.md

[7] https://www.theregister.co.uk/2020/05/09/coronavirus_tracing_app_source_code/

[8] https://github.com/nhsx/COVID-19-app-iOS-BETA/issues

[9] https://github.com/nhsx/COVID-19-app-Android-BETA/issues

[10] https://github.com/nhsx/COVID-19-app-iOS-BETA/issues/30

[11] https://github.com/nhsx/COVID-19-app-iOS-BETA/issues/20

[12] https://go.theregister.co.uk/tl/1936/-8552/how-to-accelerate-brilliant-digital-experiences-with-low-code?td=wptl1936

One would have throught...

The_Idiot

... that developing something that tells you 'someone unknown' came into potentially contagious contact with 'some somebody else-s unknown' would hardly serve the stated purpose. Equally, even if you know 'Person X' came into contact with a a bunch of 'somebody unknown-s', you're hardly going to be much further forward.

So to engage in contagion limitation you pretty much have to know Person X came into contact with Person Y, Z, F, K etc - _and_ know which, if any, of those people had been infected, or come into contact with those infected. Thus making any pretense of 'it's OK, it's all aninny... er, anumby... er, 'nobody knows who anyone being tracked really _is_' rather self defeating. If you're going to sell BS, at least don;t try to tell people they're just imagining the smell...

Re: One would have throught...

gnasher729

One would have thought that Apple and Google would have some rather smart guys working for them to figure this out.

Say we sit on the same park bench, too close together. Our phones exchange random codes identifying each other. If you get infected, you tell your app and it uploads the codes it used to a server. My phone downloads the complete list of infected phones once a day. It has one of the codes you uploaded, so my phone knows it was nearby someone who is infected.

Re: One would have throught...

The_Idiot

And yes, that sort of thing could have been a potentially viable solution. This one, as far as I can tell, isn't it. But they're still marketing it as 'serving advertised purpose' and also 'totally anonymous'. If it _had_ been the type of solution you describe, and if they _had_ implemented a full release of source code to back their claims - then maybe. But not with what I've seen and heard of _this_ code.

Re: One would have throught...

Anonymous Coward

Make no mistake, they have every intention of retaining and using that data. There have been attempts to monetise health data in the past by making it available to private companies. This data is valuable.

App code published -- but server code still secret!!

Anonymous Coward

Ah....Cheltenham still in the driving seat!!!!!!

Anonymous Coward

The NHS app from the source code released the other day keeps 28 days of data. Palantir are also involved which should raise a red flag considering they are financed by In-Q-Tel which is a venture capital group set up by the CIA. Something is not right here and I hate to be that guy with the tin foil hat,

Why, oh why...

Adair

...could we just see this coming; with bells ringing, clown shoes slapping, and full custard pie slap?

It didn't have to be this way, but somehow we just knew it would, as we peered through our fingers, hoping against hope that they might just manage to do it right. At least right enough to avoid the clown shoes and the custard pie.

And who ends up paying the price?

Re: Why, oh why...

Pascal Monett

" hoping against hope that they might just manage to do it right "

Hope springs eternal, but the NHS has, how can I say, a history as far as IT is concerned. Given that there was undoubtedly a smidgen of urgency, the fact that the app is bug-ridden and violates privacy was to be expected.

But, no worry ! There is never time to do things right, but there's always time to do things over again.

So, some time before the heat death of the Universe, there just may be a proper application that does what it says on the tin.

In the meantime, the snouts are firmly in the trough, so all is well.

IceC0ld

it really should have been put out to bidders, a competition if you like, a bounty up for grabs for the app that does what is required even, they could always add security afterwards ? at the very least it would have hopefully, gotten them three or four differing takes on the same angle, that they could then dissect and mix n match to get what they wanted.

UNLESS, of course

they WANTED it to be a complete balls up, with unimaginable consequences for the near future

isn't there an app, in Iceland IIRC, that lets you know if the person you have met, with a view to intimacy beckoning, lets you know if they are closely related to you - Iceland has a small genetic pool. why couldn't we use something like that, we all get our details added to yet another D/B, and this one includes the Y/N table for COVID infection

and now I can no longer remember if I started this thread in an honest attempt to give an option, or whether it is supposedly a piss take on the difficulties that this was ALWAYS going to engender, as it is starting to look like a it's staring into the abyss ffs :o)

meanwhile, week 8, and I remain in my bedroom ...............................

Iceland and genetic tracing

amacater

I remember reading something from somebody who was excited to learn she was descended from one of Iceland's famous early settlers from a saga.She boasted about being something like a sixth cousin and was met with "Yes, so am I - so are we all" Notably, Iceland had a major project a while ago to map genomes and so on - I can't remember if the data was eventually sold to the US when the financial scandals were rife. 200,000 Icelanders and you can do that: that's less than 1/3 of the population in my county. Also, if I recall, it's based on the government ID / Social Security registrations. It must include full personal data because otherwise you couldn't deal with Iceland's family naming system.

Doctor Syntax

"they could always add security afterwards"

Conventional wisdom is that it's very difficult to add in security afterwards. Design it to be secure from the start.

Spicer

...and how long did we have to wait for the first data breach? A week after launch of the Beta!

This would almost be comical if it wasn't so scary

Either these guys are clowns, which I don't believe, or they just don't actually care because they have ulterior motives. And I don't believe for a moment that these motives are altruistic or ethically driven by the Hippocratic Oath to save humanity from Covid-19

Pascal Monett

It's not because they don't wear the makeup that they're not clowns

It's a worry

BenDwire

It's a worry when the app seems so fundamentally flawed one would prefer the Google/Apple approach. Is this some weird example of Stockholm Syndrome ..?

Re: It's a worry

Chris G

It's a worry that NHSX are having anything to do with it.

Irongut

it took less than 30 minutes looking at the code the day it was released for me to spot multiple issues ranging from the basic to the severe, including many day one rookie mistakes. From excessive permissions including location and the ability to access all your files, to the use of multiple analytics services (Google Analytics, Google Firebase and Microsoft App Center) which means the user is not anonymous, to fundamental mistakes in the way Blootooth should be used, to simple mistakes a junior Android dev would not make like the missing minimum SDK build variable. There also appear to be bits of the code missing that prevent it compiling - considering the code they released what are they tring to hide?

This code base is not fit for purpose. The people responsible for it should be removed from Gov IT projects and not allowed to bid on more.

And, of course, we have no idea what the back-end might be up to.

mark l 2

I was sure that the government said that when they would start easing lockdown restrictions where when the number of cases were low and when the ability to track and trace was ready.

I still feel that when you have hundreds of deaths per day and the app is not ready for general roll out that they haven't yet met those requirements, but have still decided that people who cannot work from home should now go back to work. I feel they are rushing it get the economy back up and running at the risk of a second wave of infections.

Self-reporting is bound to fail

Anonymous Coward

From the government's own statistics, less than 15% of those tested for COVID-19 actually have the illness. Now presumably the vast majority of those tested must have been displaying obvious symptoms, so this gives you some idea of how many false positives the app will throw up.

Do it right from the start

Lorribot

Projects and development are often run to deliver functionality and completion in the shortest cheapest possible way.

Basic security and ongoing and lifecycle mangagability often get in the way and are convieniently ignored or deemed a BAU problem to sorted later.

GDPR, like human rights, are not some inconvienient thing to legislate around, it is there to protect us from them and other careless idiots and should be a core consideration before you even start writing code not some after thought resolved with legal nonesense.

Re: Do it right from the start

LowPay

"Projects and development are often run to deliver functionality and completion in the shortest cheapest possible way."

That is normally true. I believe the NHS is creating a product that would fall within the sphere of our FDA.

It looks like a consumer product, a smartphone, is being pressed into service as a medical device.

Over here such product development is a time consuming and extremely detailed/documented process.

Perhaps off-the-shelf cell phones don't pass muster in this particular use case.

I would have more faith in the tracking app doing its job if it's development were in hands of experienced programmers from a medical device background working for a well known medical device company. They have a habit of testing the hell out of this kind of thing prior to releasing it.

Google and Apple are not known for software or device products in the medical field.

Re: Do it right from the start

Doctor Syntax

This is a circumstance when you work with what you've got - smartphones in the hands of the public - rather than something that doesn't exist. That said you should then make best use of it which this doesn't.

Dont rely on Lizzie Dehnam!

John Jennings

She was on the select committee - the UK ICO - and quite frankly was appalling.

She wanted to be a 'critical friend' to the developers. Didn't raise the obvious issues about privacy, and didnt blink when the rights were being overridden (no opt out, request for the data held centrally, or deletion). Spent her whole time trying to justify why the ICO office should be responsible for the privacy oversight of the systems.

She cant be the 'critical friend' while being the auditor

She really should have been sacked on teh spot for that.

cantankerous swineherd

comedy gold

https://github.com/nhsx/COVID-19-app-Android-BETA/issues/14

"From examining https://github.com/nhsx/COVID-19-app-Android-BETA/blob/master/app/src/main/java/uk/nhs/nhsx/sonar/android/app/registration/ResidentApi.kt#L46 it appears that the app relies on an external HTTP server to generate a key pair, which it then stores:

..."

BlueFrag

petef

I have just had a reply from Motorola customer services confirming that my Moto G5S will not have its security level patched beyond its current Aug 2019 level. That is despite it being less than two years old. So my Bluetooth needs to remain disabled. A security level of Feb 2020 is needed BlueFrag can infect Android 8 or 9 without user interaction.

Success is relative: It is what we can make of the mess we have made of things.
-- T. S. Eliot, "The Family Reunion"