Live data from Hacker News

Apple, Google ban location tracking in apps using their contact-tracing system

reuters.com

301–310 of 568 posts

Re: Apple, Google ban location tracking in apps using their contact-tracing system

#301
post #200

Earlier quoted context omitted.

Can someone please explain to me how a “libertarian” like Peter Thiel could start and run one of the most anti libertarian companies? What are his beliefs, exactly? I mean besides “zero to one” and “competition is for losers, build a monopoly”? I wonder how much effect he had on Zuck early on. He was the first big check in. Seems it was a great match there.

There's libertarians, and then there's libertarians. Thiel is a huge fan of Hans Hermann-Hoppe, who writes things like: "In a covenant concluded among proprietor and community tenants for the purpose of protecting their private property, no such thing as a right to free (unlimited) speech exists, not even to unlimited speech on one's own tenant-property. One may say innumerable things and promote almost any idea unde…

Sounds more like fascism with the alignment of political and corporate power.

But the label is irrelevant, Thiel and Palantir's actions are anti-democratic and their involvement in any government activities immediately raise privacy and safety concerns.

Re: Apple, Google ban location tracking in apps using their contact-tracing system

#302

Earlier quoted context omitted.

While that might be an argument in general, the protocol Google and apple are working in is cryptographically secure. They provably can't back out data about you.

Is their code open source? How do you know this?

Realistically, those APIs will be analysed soon after they're available in the same way COVIDSafe was. If they do something different than what's in the design, we'll know pretty quickly.

Re: Apple, Google ban location tracking in apps using their contact-tracing system

#303
post #11

Earlier quoted context omitted.

Given that Palantir is involved, I'd not touch it with a long stick https://tech.newstatesman.com/coronavirus/palantir-covid19-d...

Seems like many countries have contact tracing apps (Australia is one) are they all based on Palantir?

The Australian app is reportedly based on an open source app from Singapore. The Australian government said it would release the source for its own version in a couple of weeks. The code is GPL, if it's this one: https://github.com/OpenTrace-community.

Re: Apple, Google ban location tracking in apps using their contact-tracing system

#304

Earlier quoted context omitted.

During a training, demonstrating how to do geo searches on license plate data from ALPRs, a detective insisted we look up their car. The hits were all more or less expected, a bunch around their home and the precinct, local supermarkets, etc. But then a weird grouping way out of town. Detective insisted it was a mistake and wanted more data, thinking someone stole his license plate (insert eye roll here). Anyways, zo…

This right here is a great argument for why "helping them use [the data they already have] more effectively" (as you've said) is probably not as great a mission as you're making it out to be.

I mean, I left?

I’m not saying it’s perfect, but scapegoating the company is avoiding the real issue, which is the government policies or the enactment thereof.

Re: Apple, Google ban location tracking in apps using their contact-tracing system

#305
post #258

Earlier quoted context omitted.

It isn't actually a law yet - that happens later this month. Instead, we've received a determination by the minister [0], which will act as a kind of back-date for when those laws are passed. > A person must not decrypt encrypted COVID app data that is stored on a mobile telecommunications device. That video shows them looking into how the data bundle is assembled, but I don't believe they actually touch it or run it…

IANAL, but I think your interpretation goes beyond what they're after. The determination is clearly aimed at data usage and prevents people from trying to decrypt the reports from other users. The whole fragment of the interview is about the data produced by the app and how it should be protected as sensitive information. I can't see anything there that would prevent you from reverse engineering "to see how any of th…

> IANAL, but I think your interpretation goes beyond what they're after.

Perhaps more than the intent, but this is a government that doesn't deserve the benefit of the doubt.

Circumventing any "access control technical protection measures" is currently a crime under Australian law (Section 116, Copyright Act). They may well consider any decompiling tools to fall under that particular law, as well as use of said tools.

In March, they pressured a university in firing someone researching into their own data breach to see how bad it is. [0] There isn't a law against de-identifying, especially when it is in the public interest, but they went ahead and threatened severe legal action anyway. Whilst simultaneously claiming that said data breach doesn't contain any personally identifiable information.

They had to be taken to the High Court to be shown that an algorithm cannot be used as evidence that a debt exists, and that decision makers actually need to do more than just trust the system. [1]

If it embarrasses them in any way, then they are not above twisting laws to suit them. [2]

[0] https://www.theguardian.com/australia-news/2020/mar/08/melbo...

[1] https://www.theguardian.com/australia-news/2019/nov/28/robod...

[2] https://www.abc.net.au/news/2020-02-28/abc-not-appealing-fed...

Re: Apple, Google ban location tracking in apps using their contact-tracing system

#306

Earlier quoted context omitted.

While that might be an argument in general, the protocol Google and apple are working in is cryptographically secure. They provably can't back out data about you.

Is their code open source? How do you know this?

Yes.

https://www.apple.com/covid19/contacttracing/

Re: Apple, Google ban location tracking in apps using their contact-tracing system

#307

I have to say, working at Apple and knowing all the hard work that goes into this and making sure your data stays private while also being able to combat this disease, it's very frustrating to read a lot of the comments here. I can understand why the public is skeptical, but I feel like as a society we've swung so far away from institutional trust that now nothing good can actually emerge. The anti-vax movement is a…

> I can understand why the public is skeptical You can understand the skepticism and yet equate the skeptical people to "anti-vax" movement? That's very sneaky of you.

"It is difficult to get a man to understand something when his salary depends upon his not understanding it." Upton Sinclair.

Re: Apple, Google ban location tracking in apps using their contact-tracing system

#308

I have to say, working at Apple and knowing all the hard work that goes into this and making sure your data stays private while also being able to combat this disease, it's very frustrating to read a lot of the comments here. I can understand why the public is skeptical, but I feel like as a society we've swung so far away from institutional trust that now nothing good can actually emerge. The anti-vax movement is a…

I've long felt like Apple is uniquely easy to distrust, due to its almost total lack of visible employees. I assume there are actual people working there, but I've never seen one, say, speak (openly) at a meetup or answer a stackoverflow question, or the like. ~Everything I know about Apple either comes from an advertisement or from a guy who talked to a guy who talked to Gruber, and I have a feeling that that makes it easier for people to assume nefarious behavior behind the scenes.

Actually, with the exception of people working on standards committees, I think your comment may be the first time I've ever seen an Apple employee openly comment in a public forum.

Re: Apple, Google ban location tracking in apps using their contact-tracing system

#309
post #184
post #3

I've been wondering about the UK contact tracing app because they seem to be deliberately misleading saying that data is secure on the phone, yet it's a centralised model, and they are using bullshit terms like "clinically secure algorithm" to describe the one-time codes; Is the source code of these apps something that could be FOI requested from NHSx seeing as it is publicly funded by the tax payer? Also they've alr…

It looks like you won't have to petition for it. According to https://www.ncsc.gov.uk/files/NHS-app-security-paper%20V0.1.... , "We intend to open source our codebase once the first release is finalised. The documentation accompanying that release will supersede this paper." and from https://www.ncsc.gov.uk/blog-post/security-behind-nhs-contac... , "The Secretary of State has also committed to making the source code…

Sounds like there is no intention to deliver the source on release, and once the release has been out for a couple of weeks, the benefit of public review of the source code drastically diminishes.

The source code should be released before the public release of the binaries, not after, and not doing so means they're trying to hide what the app does from timely public discourse.

Releasing a tarball (even if it lacks the tools to build it) isn't that hard, is it?

Re: Apple, Google ban location tracking in apps using their contact-tracing system

#310
post #142

Earlier quoted context omitted.

That claim is worthless when the software is closed source. It's impossible to verify.

Claims aren't worthless, they'd be breaking the law if they lied. Apple has a pretty decent incentive to not break the law (PR mostly, but also fines), so I would bet they're telling the truth here.

And as we all know, and history shows, those incentives ensure corporations never break the law.
Post reply on HN