AusSMC Media: COVID-19 App

EXPERT REACTION: Coronavirus tracing app

Several politicians have raised concerns about the COVID tracker, the Federal government app which will be available in the next couple of weeks, to help track down people who may have been in contact with someone with the coronavirus. Below Australian experts comment.

Rachael Falk is CEO of the Cyber Security Cooperative Research Centre. The Cyber Security CRC has been playing an active role in reviewing COVID-19 tracing app and have been working with the Australian Government's Digital Transformation Agency and others to do this.

"We need more time and information before we can give this a final thumbs up, but the app already passes the early tests of security and privacy.
 
It is right that Australians take a conservative approach to protecting their online security and privacy.
We have already begun scrutinising the source code to ensure Australians who use it are kept safe.
 
The Cyber Security Co-operative Research Centre exists to link government, business and universities. Our funding comes partly from the Commonwealth, so it’s appropriate that our cybersecurity experts scrutinise this app.
We will advise the Government whether and how the app can be improved to guard the safety of Australians who use it."
 

Conflict of interest: The Cyber Security CRC has been playing an active role in reviewing COVID-19 tracing app and have been working with the Australian Government's Digital Transformation Agency and others to do this.
-----------

Dr David Glance is from the University of Western Australia Centre for Software and Security Practice

"We have yet to see the details of Australia’s app but understand that it is based on Singapore’s TraceTogether COVID-19 tracing application. There are some privacy concerns with this approach because of the role of the health authorities in collecting and using the information gathered and the use of personally identifiable information.
It has a major deficiency when operating on iPhones and this will make it hard to use even for those who want to contribute to the Government’s efforts to relax present restrictions. There are also unknown security issues with the application that can only be discovered once the application is made available. Whilst I agree that using this technology will help in the tracing efforts and is possibly necessary under the current environment, strong assurances about its limited use and making the right choices regarding its implementation will be critical to its adoption and use."
 

David has not declared any conflict of interest


------------------
 

Professor Katina Michael is from the Faculty of Engineering and Information Sciences at the University of Wollongong

  • How does the app work?

"The contact and trace app works using Bluetooth Low Energy (BLE) technology. When two users who have downloaded the App and have Bluetooth enabled come into close physical proximity (a few meters) for a given length of time, their smartphones communicate sending one another a random identifier that is encrypted on each handset and stored for 21 days. The app automates "contact tracing" as done manually by health organisations presently including: contact identification, contact listing, and follow-up. Once someone is confirmed of having COVID, then their handset is interrogated for the stored physical social network, and corresponding records are decrypted, and individuals on the list notified." 

  • Will it be a privacy risk?

"The alleged system does not retain personally identifiable information (PII) but a privacy impact assessment is forthcoming mid week. Despite the system being pseudo-announced as 'mandatory', it is now clear that it is voluntary and citizens will have a choice whether to download the app. The usefulness of the app will be determined by the percent of the population that adopts the app, remembering that not everyone has a smartphone.
 
Definitely, after a confirmed case has been determined, someone's privacy is 'in practice' encroached; as well as their corresponding physical social network, whether family, friends, colleagues, or strangers. But it has to be noted that this is done willingly, with the participants' consent. A user is entrusting the health organisation, or government agency, with their privacy, allowing access to their handset data but that is deemed proportional given the pandemic crisis. What the government is trying to achieve in essence is a COVID-19 response app; but we need to be cognizant that privacy, security, trust and safety are embedded into the functional design. But sadly, a consultation process has been lacking. It seems very top-down to date."

  • What happens to my data?

"Your data is stored on your handset, it allegedly never leaves the device unless you or someone in your physical social network is determined as having COVID-19. Every 21 days, data is deleted from the handset. But once voluntarily accessed, the data will need to be at least temporarily stored on a third party database, whether that is the health organisation or another government agency, it is not known. It should be noted, that the system will most likely utilise the bluetrace.io application which will at least handle the capability side of things, but not much is known about this beyond the company's whitepaper online."

  • What level of uptake is needed to make it possible to lift restrictions?

"I don't think a participation rate in the app, whether 40%, 60% or 80% can aid in lifting restrictions but it is certainly true that the greater the uptake, the more effective the app will be in meeting its primary objective. At best the app is "after the fact". It will help in reducing transmissions possibly, but certainly not in eradicating COVID. It will also allow for early intervention of suspected carriers of COVID, and preparing the medical supply chain and health infrastructure necessary in a given location to better respond to local outbreaks. But that is if it actually does work, of which evidence is lacking. It does make sense in principle but where are the successful use cases?
 
We have to be very careful not to confuse the issue as well. Apps don't reduce transmission, they help to identify individuals who have come into contact with people who are a COVID confirmed case. If we relax social distancing measures too quickly, with or without the App, we will most likely find ourselves going through a second smaller peak of infection. And we are trying to avoid that. 
 
The downside of an app like this may well be that people with COVID feel discriminated against. There has been quite a bit of discussion around the fact that some people have tested positive to COVID-19 but do not have symptoms of COVID. In addition, it has been clear that multiple surveillance capabilities may well be used to enforce quarantine for those who do not adhere to self-isolation using anklet bracelets or other trackers. Note, this is not a part of the original contact and trace aims. Digital immunity certificates have also been spoken about, and clearly this makes some people uncomfortable."

  • Is it hackable?

"The technologist in me says that any system is hackable. I do not believe that hackers would be interested in disclosing the names of COVID sufferers, or those in their physical social network. But certainly hackers will have a field day with Bluetooth-enabled handsets. When Bluetooth first was introduced into handsets, a lot of people had 'fun' with innocent hacks. Some of these began to turn nasty when an unsuspecting user had their contact list wiped, after pressing on a message pop-up, or a virus that made the handset dysfunctional for use. And that is no laughing matter. No one is talking about electromagnetic interference at the moment, and they seem to have forgotten what enabling Bluetooth can actually do. We know as average consumer users of this technology, that pairing devices, can sometimes end up in some tricky operational scenarios when devices are shared or otherwise."

  • How does the apps tracking ability differ to other apps such as Facebook and Google Maps?

"The contact and trace application that the Australian federal government is introducing is not a tracking app. it is a good question however to ponder on. We constantly are streaming personal information to both the Facebook and Google platforms. What does this mean for our personal privacy? Google and Apple in a new initiative are trying to offer an operating system level contact and tracing feature that will not require a user to download yet another app, which might well be out of date. By doing this, they will just be seeking consent to usage of the App by the end-user making it a simpler process. It seems a good time to talk about Public Privacy partnerships (PPP) as they seem to be garner force in the background but with little public engagement with citizenry."
 

Katina has not declared any conflict of interest 

----------------

Associate Professor Frank den Hartog from the School of Information Systems and Technology Management at UNSW Canberra
“Many questions around this app cannot be answered by independent experts as long as the service specifications and the code are not published. Actually, the service specifications should have been published a long time ago, followed by an open expert consultation for feedback to the service specification and an assessment of the 60+ apps that already exist worldwide. Then choose a promising candidate, take it from there, publish the code, and ask for another open expert consultation.
Part of that consultation would be a privacy and a security assessment. The outcome of which would be more broadly accepted by the public than an assessment by the government or parliament itself. Having said that, I think Australians should be prepared to accept some trade-off between privacy and public health here. However, that does not preclude a thorough minimisation of privacy risks to a bare minimum.
Also, everything is hackable. But publishing the code would allow experts to review it on vulnerabilities and make it more secure. How large the uptake needs to be to make it possible to lift restrictions mostly depends on how effective the institutions react given the data. This is hard to predict. The app itself only generates data.”

Frank has not declared any conflict of interestHe is contactable via Ebony Stansfield from UNSW media,  

-------------

Professor Dali Kaafar is Executive Director of Optus Macquarie University Cyber Security Hub at Macquarie University
"In essence, while the technology on which the Australian government COVID-19 tracing app will be built is providing privacy from other users of the app, it does not provide any privacy from the central authority collecting and processing the data. The authority will certainly be able to collect the social graphs (and optionally visited locations) of not only individuals who have been diagnosed with COVID-19 (and who might have given at that time their consent ), but also the central server can know the private data of a user even if they are not infected.
Once a user has tested positive for COVID-19, they need to provide consent to the server to retrieve and decrypt their data log. This enables the server to obtain the identities of the App users that have been in contact with the infected user. These potentially uninfected users are no longer in control of their privacy. This brings some serious issues with regards to consent and transparency of use of information stored on the local devices and pushed to the server. 
 We made the recommendations in the form of simple and easy-to-fix techniques to the government so that the app provides more privacy from the Central Authority, and in particular to enforce the notions of explicit consent-based data collection about individuals, as opposed to implicit consent (that is assumed just after users install the app).
 We also believe that contact tracing apps should be developed without a centrally controlled database that holds private information on individuals.
There are a number of proposals for contact tracing methods which respect users' privacy, many of which are being actively investigated for deployment by different countries."
Dali has written more on this issue here: https://www.mq.edu.au/about/about-the-university/offices-and-units/optus-macquarie-university-cyber-security-hub/news-and-events/news2/news/covid-tracing-app/COVID-Tracing-App-11.pd

Dali has not declared any conflicts of interest.
-----------------------

Dr Belinda Barnet is a Senior Lecturer in Media and Social Media Major Director at Swinburne University
"If the app is implemented in Australia as it was in Singapore it does not require or request your GPS location. It simply logs which devices have been in close proximity to you. Importantly, TraceTogether stores this data on your own device and only “shares” the data with the authority’s server if you test positive and if you consent. So the data doesn’t get shared unless you test positive.  
My main concerns were around data privacy and also whether or not the app itself would be effective as it cannot replace manual contact tracing. I’m pleased that the government has agreed to make the app open source so that researchers can look at the code and at its security and privacy implications. I’m pleased that they will not make it mandatory. I hope that they simply use TraceTogether rather than making their own. 
 
I think it will be very difficult to get upwards of 40 per cent simply because people don’t trust the government with their data now. As a result of projects like My Health Record and the Census debacle, there is a general perception that this government uses our data without our consent. So it’ll be a hard sell." 
 

Belinda has not declared any conflicts of interest.-----------------------

Associate Professor Clive Harfield is from the Institute for Cyber Investigations & Forensics at the University of the Sunshine Coast
"Assertions that these apps do not provide live tracking data disguise the whole point of these apps, which is to trace - and so track - contacts between people and thereby identifying individuals who may have been infected with the virus but are not yet presenting symptoms. The purpose of contact tracing is to track the movements of individuals (all be it historically rather than in real-time) and identify where they have been, who they have been with, and where they might have spread the contagion.
The usual expectation that no one is obliged to reveal their medical history (even to medical practitioners) is outweighed in the circumstances of a pandemic because of the threat that infected individuals pose to the wider community. But this justification for (medical) privacy intrusion ceases once a potentially infected person has been identified and put in touch with medical authorities.
The vulnerabilities of any app are:
• Unidentified aspects of the software coding that enable hacking or coincidental uses for the app; and
• Aggregation of the data collected by the app with other data sources, particularly those routinely gathered – and shared – in relation to use of mobile devices.
Once gathered and collated, any data is vulnerable to unauthorised access through information sharing between entities or agencies who (mistakenly) believe they are authorised to share such information, or to unauthorized access through hacking. Digitized records forming part of the My Health Record database are to be retained long after the patient is dead (30 years I think): how long is the contact tracking data going to be retained, storage and retention being significant data management/cybercrime vulnerabilities?
Making the app source code publicly accessible would enable transparent scrutiny of the app, its intended functions and any unintended capabilities it offers.
More needs to be explained in detail about how the app actually works, and who will have access to the data it generates, where the data will be stored, and - in each case - for how long.
Individuals strictly adhering to the ‘stay at home’ protocols arguably do not need to down-load the app. Keeping a written record of your daily contacts and where you have been, if anywhere, would serve the purpose just as well should an individual test positive for the virus.
Personal written records are not vulnerable to hacking or other digital data misuse. Personal written records are not vulnerable to the possibility that two uninfected app-users who happen to be near each other could trigger a false positive.
Even allowing for the fact that these are emergency circumstances, investing in the direct benefit of increased testing for the virus seems more worthwhile – and morally more justifiable - than increased investment in surveillance technologies which offer, at best, an indirect benefit with accuracy short-comings."

Clive has not declared any conflict of interestHe is contactable via Janelle Kirkland, Media Relations Coordinaton--------------------
 

Dr  Lewis Mitchell a Senior Lecturer in Applied Mathematics at the University of Adelaide.

  • How does the app work?

"By saving on your phone a list of IDs corresponding to other phones you’ve come close to. This is measured by Bluetooth, not GPS. The contacts are stored as lists of random letters and numbers, not as names or phone numbers. If you are diagnosed and consent to share your data, you can share this list with state health authorities, who can then call those potential contacts and conduct a contact tracing interview with them as they do currently."

  • What happens to my data?

"Nothing whatsoever, unless you are diagnosed as having COVID-19, and consent to share your data, or are a close contact of someone who has been diagnosed. In that case, and in that case only, your name, age, phone number, and postcode, will be shared with state health authorities, who will call you for a contact tracing interview. Otherwise, your information stays on your phone, and is never shared with anyone."
 

  • What level of uptake is needed to make it possible to lift restrictions?

"Not clear, because this is a complex question for the government to answer, based on a wide range of health and economic advice. The government is aiming for 40 per cent uptake, mathematical modelling suggests that 60% or more is desirable. But any uptake more than zero has the potential to help."

  • Is it hackable?

"No more than your Facebook or Twitter app is hackable. And even if it were, all that could be gotten is a list of ID codes of phones you’d been in close contact with — some random numbers and letters — not names, phone numbers, or locations."

  • How does the app's tracking ability differ to other apps such as Facebook and Google Maps?

"It differs utterly, in that the app collects zero location information about you. All that is stored on your phone is a list of contacts made with other people who have installed the app."
 

Lewis has not declared any conflicts of interest.

Previous
Previous

After COVID how can tech help us

Next
Next

Coronavirus Contact Tracing App Will Reveal Who You Hang Out With