Live data from Hacker News

Dissection of COVIDSafe (Android): Australian government's contact tracing app

docs.google.com

251–260 of 271 posts

Re: Dissection of COVIDSafe (Android): Australian government's contact tracing app

#251

Earlier quoted context omitted.

Mike my concern as a scientist about this app is it may not help much at this point. If it is only picking up people you spent more than 15 minutes talking to it is going to miss a lot transmission events. Do we have the contact tracing people to actually make use of this data? Even if we did I can’t see how we are going to avoid the need to interview each positive case to find all the people they came into contact w…

> 15 minutes talking to it is going to miss a lot transmission events. Honest question (as a scientist myself): is there any serious non-preprint literature on the time needed for a transmission event (I assume estimates will vary wildly)?

Bluetooth penetrates walls, and travels some distance in all directions, so it will also record a lot of false transmission events, for example in blocks of units, offices, and on public transport. Most transmissions are to immediate family, who are easy to trace manually with the existing procedure.

Re: Dissection of COVIDSafe (Android): Australian government's contact tracing app

#252
post #35

I believe the government, PM and various ministers have said the code will be released. My sources also say exactly the same. They’re obviously operating with extreme urgency to get the app out. For you. Give them a few weeks to clean up code and release it (which is very normal) - but in the meantime, here are some tips: - Turn the HN angry mob mode off - it’s not helpful. We’re all in this together. - Commend the g…

I would love to trust them more, but the Australian government does not have a good track record with regards to privacy. Two such recent examples: - Australian's browser history is being provided to law enforcement even though that practice was excluded from the original intent and law [0] - Australia passed laws in 2018 which enable law enforcement to compel tech companies into inserting backdoors into their softwa…

> Australia passed laws in 2018 which enable law enforcement to compel tech companies into inserting backdoors into their software

No, it didn't. The bill had language specifically intended to address these concerns. Read the bill [0]. The relevant part is under Part 15 > Division 7 > 317ZG, which you can also see at [1].

This section explicitly forbids the government from requesting that a provider "build a systemic weakness, or a systemic vulnerability, into a form of electronic protection". It also forbids the government from asking a provider to preserve such a weakness.

It also explicitly indicates that this definition includes:

- "a reference to implement or build a new decryption capability in relation to a form of electronic protection"

- "a reference to one or more actions that would render systemic methods of authentication or encryption less effective"

So no, the government did not pass a bill that allows them to request encryption backdoors.

These weren't even amendments made later, this language was present from the very first version of the bill [2].

The reporting around this was simply atrocious and made me lose a lot of respect for news sources I'd otherwise have thought were respectable. Just read Wired's article:

"Systemic vulnerability means a vulnerability that affects a whole class of technology, but does not include a vulnerability that is selectively introduced to one or more target technologies that are connected with a particular person," the Australian law says. In other words, intentionally weakening every messaging platform out there with the same backdoor wouldn't fly, but developing tailored access to individual messaging programs, like WhatsApp or iMessage, is allowed."

They cherry-pick a quote from part of the legislation but just so happen to ignore the rest of section 317ZG, which invalidates their claims.

Other publications were even worse, they couldn't even point to which parts of the law were objectionable.

If you would like to disagree with my assertions, please provide evidence-based claims, as I have.

[0]: https://www.legislation.gov.au/Details/C2018C00495

[1]: http://www5.austlii.edu.au/au/legis/cth/consol_act/ta1997214...

[2]: https://www.aph.gov.au/Parliamentary_Business/Bills_Legislat...

Re: Dissection of COVIDSafe (Android): Australian government's contact tracing app

#253
post #95

Earlier quoted context omitted.

Interpreting legislation without any common law / precedence is difficult. However as a general rule, if there are two laws that are conflicting (such as previous anti-privacy laws vs the proposed safeguards) the most recent enacted law applies, especially if it is specific. So while I’m by no means a fan of the erosion of privacy that this government has done previously, the proposed safeguards would be effective an…

Is "latest rules" truly what happens? Or if the law explicitly allows X and also explicitly disallows X, then a person would not be convicted, rendering in this case the latest safeguards in effective?

To say it's complicated is an understatement, there are literally entire books written about it [1]. It's rarely that simple but if one act states X is allowed and another act of the same jurisdiction states the exact opposite (assuming both laws are legally valid), then the most recent law prevails. The principle behind it is that the current parliament/legislature shouldn't be able restrict what future parliaments make laws on (the exception being the Constitution). Otherwise the government of today could make a law thats says 'X is illegal and no law can ever change this'.

[1] https://www.federationpress.com.au/bookstore/book.asp?isbn=9...

[edit: typos]

Re: Dissection of COVIDSafe (Android): Australian government's contact tracing app

#254
post #145

I'd love to know where 15 minutes exposed came from. Feels like a value imputed from a join over battery drain and usefulness. I thought five minutes made more sense. If you are 15 min within 1.5m of a stranger in most Australian states you're probably mildly in beach of social distancing.

15 minutes was part of the definition for a casual contact 2 months ago, a lot earlier than the app and the social distancing rules.

https://www.health.gov.au/sites/default/files/documents/2020...

Re: Dissection of COVIDSafe (Android): Australian government's contact tracing app

#255

Earlier quoted context omitted.

> 15 minutes talking to it is going to miss a lot transmission events. Honest question (as a scientist myself): is there any serious non-preprint literature on the time needed for a transmission event (I assume estimates will vary wildly)?

Bluetooth penetrates walls, and travels some distance in all directions, so it will also record a lot of false transmission events, for example in blocks of units, offices, and on public transport. Most transmissions are to immediate family, who are easy to trace manually with the existing procedure.

The government says that if you are party to a (genuine or false) transmission event, you will be contacted by phone, but you will not be told the name of the person who tested positive to the virus. So how will you know if the event is genuine or not? It could be your neighbour on the other side of a common wall, or a colleague who works in the office next to yours -- in either case, no transmission. Also, they say you may be "advised to self-isolate". This is disingenuous -- you are more likely to be ordered to self-isolate under penalty of fines or gaol time. No mention of that in the glossy "Utopia" style promotional video, just happy young models having coffee.

Re: Dissection of COVIDSafe (Android): Australian government's contact tracing app

#256

Earlier quoted context omitted.

> Most people on HN are under 65 and thus will only get mild symptoms and likely just be out for a few days. This is the most likely case for people how are not vulnerable, but by no means a sure thing. Plenty of people without preexisting conditions have died or had to be hospitalized for days or weeks. Data is a bit difficult to filter, but as an example 4.5% of deaths in NY are from the 18-44 age group[1]. Presuma…

Understand I'm replying not because I think people should necessarily want/try to infect themselves with the virus, but because I'm against spreading misinformation and a misuse of statistics. Australia is approaching 100 deaths and has several thousand confirmed cases through more widespread testing than new York, doing so at a higher and wider rate than New York who's stats/testing and medical regime show signs of…

I appreciate this. I have not had an easy time finding any data that goes deeper than the 0.2% data point, which clearly doesn't give a full picture because it doesn't dive into the effect of comorbidity. Your sibling post links to data that puts the risk for people under 40 without comorbidity at roughly 1/6 of the 0.2, which is a big difference. Do you have any data, or any sources for your comment about the situation in Australia.

Re: Dissection of COVIDSafe (Android): Australian government's contact tracing app

#257
post #35

I believe the government, PM and various ministers have said the code will be released. My sources also say exactly the same. They’re obviously operating with extreme urgency to get the app out. For you. Give them a few weeks to clean up code and release it (which is very normal) - but in the meantime, here are some tips: - Turn the HN angry mob mode off - it’s not helpful. We’re all in this together. - Commend the g…

“Give them a few weeks to clean up code and release it (which is very normal) ”

In the world of security critical systems, this is completely abnormal.

Re: Dissection of COVIDSafe (Android): Australian government's contact tracing app

#258

Earlier quoted context omitted.

> 15 minutes talking to it is going to miss a lot transmission events. Honest question (as a scientist myself): is there any serious non-preprint literature on the time needed for a transmission event (I assume estimates will vary wildly)?

Bluetooth penetrates walls, and travels some distance in all directions, so it will also record a lot of false transmission events, for example in blocks of units, offices, and on public transport. Most transmissions are to immediate family, who are easy to trace manually with the existing procedure.

Authorities here were quoted saying that family transmissions are 25% of the cases. Now I wonder, what is part of the remaining 75%?

Re: Dissection of COVIDSafe (Android): Australian government's contact tracing app

#259
post #192

Earlier quoted context omitted.

My feeling is that they are getting it right this time, as science and medicine is still trumping politics in Australia's COVID response. (Though that's beginning to change.) Getting it right this time means the Government doesn't have any excuses going forward. Overall Australia is genuinely doing a great job in relation to COVID, mainly because the Government had the good sense to put the experts center stage and g…

Requiring a phone number may be in breach of existing legislation, particularly that which resulted from the No vote to the Australia Card in the 80's. Those anti-id laws were ratified in 2005/2006. https://www.aph.gov.au/About_Parliament/Parliamentary_Depart... This tech can and should be using crypto random hashes rather than phone numbers. The authorities don't need to call anyone, let the app and the fully anonym…

Particularly when we can't (easily) have disposable or non-identifying phone numbers in Australia: https://www.acma.gov.au/acmas-rules-id-checks-prepaid-mobile...

Re: Dissection of COVIDSafe (Android): Australian government's contact tracing app

#260
post #233

Earlier quoted context omitted.

You've really lost me with > You can chose to get the virus That wasn't your original argument and this does nothing to stop individual people getting the virus. And the source code is worth nothing. The legal structure is already there to have the app changed without anyone being notified. If they released an entire buildable set of source that I could use to build and install the app myself, maybe. But that's about…

do you make the same requirement of all software you are using? If not, why would this particular one be differently treated? Location tracking is indeed a dangerous piece of information. But in the short time that the gov't had to face the issue, the best option is to do this tracking to re-enable the economy. Until proven otherwise, it would be wise to not assume there's already malware. I'm not saying there isn't,…

> why would this particular one be differently treated?

- Because the issuer has vastly more ability to use the app and the data it might collect in ways that impact you.

- Because it's the first app of this kind and scale being issued by the government in Australia.

- Because it's being pushed onto as much of an entire population as possible with great urgency, limiting the time and opportunity for proper precautions to be taken.

- Because the issuer has an objectively _terrible_ track record on technology and privacy related matters.

- Because the ratchet effect means that once granted, privileges are highly unlikely to be ever rolled back.

> I would be much more scared of the unknown apps from dodgy shops

You shouldn't be. No matter how bad an adware mobile game is, the publisher can't put you in jail.

Post reply on HN