Live data from Hacker News

Dissection of COVIDSafe (Android): Australian government's contact tracing app

docs.google.com

231–240 of 271 posts

Re: Dissection of COVIDSafe (Android): Australian government's contact tracing app

#231

Earlier quoted context omitted.

I would love to trust them more, but the Australian government does not have a good track record with regards to privacy. Two such recent examples: - Australian's browser history is being provided to law enforcement even though that practice was excluded from the original intent and law [0] - Australia passed laws in 2018 which enable law enforcement to compel tech companies into inserting backdoors into their softwa…

Income tax was introduced as a "temporary measure" to pay for WWII. Fool me once shame on you, fool me twice, shame on me.

I assume you mean WWI? https://en.wikipedia.org/wiki/Income_tax#Timeline_of_introdu...

If we're talking Australia. If the US, well... Civil War.

But to the sentiment of the comment, I completely agree. That is explicitly why we need the "burn the system down" type of people that I mentioned. they bring to light these kinds of topics and considerations.

Re: Dissection of COVIDSafe (Android): Australian government's contact tracing app

#232
post #91

It's interesting to see these tracing app discussions crop up all over the world at the moment. In Germany it quite literally took dozens of public interest groups, two weeks of media attention, EU guidance and an open letter by hundreds of scientists to make the government switch from central data collection to an acceptable decentralised approach. The amount of misinformation put out by lobby groups in the process…

> In Germany it quite literally took dozens of public interest groups, two weeks of media attention, EU guidance and an open letter by hundreds of scientists to make the government switch from central data collection to an acceptable decentralised approach. Interesting. Do you have any pointer on the current German approach? I've been looking at the Robert protocol from Inria+Fraunhofer, and I'm not sure I like the c…

This happened over the weekend so details are pretty vague and mostly available in German. I'd expect more to follow in the next few days, official statements didn't yet talk about who will take over implementation I believe.

But w.r.t. the Robert protocol, that's the PEPP-PT one that was pushed against. Differences between Robert and the proposal for Germany were minimal. While there are a few at the moment I expect the solution to work with DP3T / integration of the Gapple APIs. Future travel in mind it wouldn't make much sense to develop something else at this point imho.

Re: Dissection of COVIDSafe (Android): Australian government's contact tracing app

#233
post #42

Earlier quoted context omitted.

Did you know that on iOS it doesn’t even ask for location, and on Android that’s required for Bluetooth? The source code will show you what is done with that (as others who have decompiled it already have shown it doesn’t use the location anywhere). You can choose to get the virus - but that’s a pretty silly choice IMHO. And if you do, please stay home and don’t give it to anyone else.

You've really lost me with > You can chose to get the virus That wasn't your original argument and this does nothing to stop individual people getting the virus. And the source code is worth nothing. The legal structure is already there to have the app changed without anyone being notified. If they released an entire buildable set of source that I could use to build and install the app myself, maybe. But that's about…

do you make the same requirement of all software you are using? If not, why would this particular one be differently treated?

Location tracking is indeed a dangerous piece of information. But in the short time that the gov't had to face the issue, the best option is to do this tracking to re-enable the economy. Until proven otherwise, it would be wise to not assume there's already malware. I'm not saying there isn't, but given the probabilities, it's unlikely, while the health and economic benefits are high.

And the source code is going to be released. It's easy (for a professional software engineer) to track down changes to the original code if they released a bad/altered version of the source that doesn't match the released version. And there'd be a track record, and it will be plainly obvious.

I would be much more scared of the unknown apps from dodgy shops that offer their apps for free in exchange for all your contacts, file and camera access.

Re: Dissection of COVIDSafe (Android): Australian government's contact tracing app

#234
post #222
post #216

Earlier quoted context omitted.

> That's incorrect. The only crime that could be a valid reason for using the data is a breach of the emergency biosecurity laws You haven't fully understood what I tried to convey. Whilst it is true that the data can only be copied from the data store for a restrictive reason, such as ensuring the security of the data store, once it is outside that store, it is no longer protected by the limitations. So this sequenc…

> Once it leaves, it is no longer protected. Unless there's something I've missed entirely in the regulation, there's nothing that says the data loses its restrictions once it moved. Happy to be corrected and pointed to the specific clause, I just don't see it. Section 3: "COVID app data is data relating to a person that...has been collected or generated through the operation of an app... and is, or has been, stored…

> Unless there's something I've missed entirely in the regulation, there's nothing that says the data loses its restrictions once it moved.

It isn't explicitly stated, which is the point. We only have the data defined two ways: In the Data Store, and on a phone. Once downloaded from the Data Store, it is outside the definitions used within the bill.

This statement is the big one:

> However, it does not include information obtained, from a source other than the National COVIDSafe Data Store, in the course of undertaking contact tracing by a person employed by, or in the service of, a State or Territory health authority.

If the data was at one time obtained from the Data Store, but this new location is used as a source, it is no longer under the definitions of the bill.

Re: Dissection of COVIDSafe (Android): Australian government's contact tracing app

#235
post #74

Earlier quoted context omitted.

IIRC, Fdroid rebuilds all the Android apps they host from source so they can be sure their source really matches the app. Actually, this is also what all good Linux distros do with all their software.

I'm not aware of any Linux distros with 100% reproducible builds, though Debian is actively working on it and getting closer.

The distros can be sure without full reproducibility, since they built it. The users are still required to trust the distros built what they said they would though.

Re: Dissection of COVIDSafe (Android): Australian government's contact tracing app

#236
post #125

Earlier quoted context omitted.

That's a false dichotomy. They could be totally fine with the intent of this app, but concerned with its potential secondary effects. And "something they did in the past" suggests they have stopped doing it.

> "something they did in the past" suggests they have stopped doing it. No it doesn't. All evidence of their proclivities is from the past. It means they have form, a record, of bad behaviour. Remember how the use of the Tax File Number was going to be strictly limited? And have you noticed you cannot scratch your bum without quoting it now? Mission creep is a thing. My own impression from observing his public behavi…

Yes, and Scotty will use the crisis to lower company tax and regulations, whilst thousands of poor souls line up at Centrelink. It's sad. The app is poorly conceived and probably useless. This is how we sleepwalk into a surveillance dystopia. But if it tracks politicians' illicit dalliances and time with lobyists, property developers and tax haven financiers, that could be useful. Just need a bureaucrat to do a copy and paste, then send to Wikileaks.

Re: Dissection of COVIDSafe (Android): Australian government's contact tracing app

#237

Earlier quoted context omitted.

This is nuts. A 30yo gets sick, infects a 60yo who goes to hospital and lands in ICU. 30yo then gets unrelated disease (chain saw accident. Burst appendix. Slipped in the shower.) Goes to hospital. Repeat this often enough and suddenly you have a crisis in which there are not enough health care workers and beds, and now all ages are dying equally. The idea that young people are not affected by this is just braindead…

But we aren’t all in it together. It’s the young loosing jobs, facin a lifetime of higher taxes, moving to a world of mass surveillance and digital dictatorships.

> moving to a world of mass surveillance and digital dictatorships.

that has already happened if you use any website that has google analytics or facebook. Ad for digital dictatorship - is it any different if the dictatorship has a friendly name like google?

I think you're conflating many different issues together: inequality of income, and societal injustice, with the actions needed to return economic activity back to a semblance of normalcy. It's as though you're asking for economic reforms as part of the economic life-line.

Re: Dissection of COVIDSafe (Android): Australian government's contact tracing app

#238
post #35

I believe the government, PM and various ministers have said the code will be released. My sources also say exactly the same. They’re obviously operating with extreme urgency to get the app out. For you. Give them a few weeks to clean up code and release it (which is very normal) - but in the meantime, here are some tips: - Turn the HN angry mob mode off - it’s not helpful. We’re all in this together. - Commend the g…

1. I trust this government no more than Mr Turnbull was father of the internet in Australia because he was the legal counsel for Ozemail, or many other denial-of-service attacks & census design (IBM) failures they have presided over.

2. What was this App developed in? Is the user interface UX. Is the back-end Xmarin, C++, Java, Objective-C, Swift or what? What API/s &/or Pods were used to achieve encryption and bluetooth handshake?

3. Source code? Really? What do you expect to see. Most usage of APIs and Frameworks explicitly hides the implementation details from the App. These libraries of independently compiled software can be enormous. People are asking for specifics but will be delivered a haystack. Good luck with that.

4. The open source code will be ripped off and repurposed for school / work attendance rolls or dating App hook-ups. Surest way to expose software to malevolent hackers is to give them the source code.

5. Careful what you wish for.

Re: Dissection of COVIDSafe (Android): Australian government's contact tracing app

#239
post #207
post #154

Earlier quoted context omitted.

> So while I’m by no means a fan of the erosion of privacy that this government has done previously, the proposed safeguards would be effective and not just empty words (at least legally speaking). Currently, they are empty words, legally speaking. The legal text that contains the safeguards is here [0]. It doesn't have most of the safeguards that Hunt announced. They're a pipedream. For example, the minister said th…

That last point is wrong – section 6 of the determination says that “a person must not collect, use or disclose COVID app data“ unless it is for one of the whitelisted purposes in subsection (2). COVID app data includes data that “has been” stored on a phone.

If the data is moved, on the Data Store is no longer the source, because you're getting that data from a secondary place, it is specifically excluded:

> However, it does not include information obtained, from a source other than the National COVIDSafe Data Store, in the course of undertaking contact tracing by a person employed by, or in the service of, a State or Territory health authority.

Re: Dissection of COVIDSafe (Android): Australian government's contact tracing app

#240
post #66

Earlier quoted context omitted.

This is more a stand on principles against governments rather than if the app is actually malicious in nature. People are rightly making a stand that a project of this nature should require at the bare minimum for source code to release concurrently with protection laws. Blame successive governments if individuals aren't overly welcoming to putting their blind faith in promises of a government that has let them down…

Exactly this. The Aus Gov - especially the current one is massively lacking in trust. Encryption laws, metadata laws. Scope creep on metadata access (ie local councils, horse racing bodies). Lack of transparent reporting when these laws are in use. Raids on journalists. Not to mention their lack of transparency over bushfires, sports grants, angus taylor's family connections with mining / paying $90m? for water to as…

Agreed -- trust has to be earned, but definitely hasn't been. Quite the opposite. I thought it was very unfortunate that the Australian Nurses' Association was asked to provide their endorsement of the government BS spin at the launch of the app. Wasn't surprised that the AMA did though. The promotional video is hilarious -- indistinguishable from an episode of "Utopia" -- LOL.
Post reply on HN