Live data from Hacker News

Massachusetts health notifications app installed without users’ knowledge

play.google.com

91–100 of 407 posts

Re: Massachusetts health notifications app installed without users’ knowledge

#91

It is obvious that we need better legislation to deal with all the new possibilities that technologies have opened. The installation of this app, even done with good intent, open a lot of questions on what should be possible or not to be done by government and corporations. When you get a device with pre-installed, uninstallable, or auto-installed apps. What are the rules? > "By enabling this service, you can be quic…

If you think legislation is the answer, I’ve got a bridge to sell you. Who do you think writes the legislation and hands it to X representative? How niave...

HN crowd has fallen pretty far. Used to be WE build the things that make our lives better and now the top comment is calling for some ethemeral they to come up with legislation?

That’s BS. And, antithetical to any builder/havker ethic.

We build the world we want.

Re: Massachusetts health notifications app installed without users’ knowledge

#92

Google and apple install tons of software basically without consent (os updates) , so an app being pushed like that is not surprising. It is worrying however that tech people dont seem to realize how great their tools are for totalitarian states , which push apps and spying much worse than this to their subjects. We really need to talk about users owning their devices and their software rather than leasing them. Ther…

You are explicitly allowing to install updates in phone's settings. It is made painfully clear.

The question here is about what mechanism Google used to install an app, can it be disabled, and what other kind of apps Google is capable of installing silently on the devices?

Re: Massachusetts health notifications app installed without users’ knowledge

#93
post #84
post #79

Earlier quoted context omitted.

> In this case it seems that the same goal could have been better achieved by SMS that do not depend on the brand of your phone. The dependency on proprietary app stores and OSs seems a risk for the continuation of a free and reliable communications. While installing an app without users consent can be as questionable as you want, the point about these apps are not the notifications itself but about the contact traci…

This sounds worse to me? Rather than violation of a relatively small privacy (phone number), you instead get timestamp social graph interactions in the physical world. This seems like fat more extreme an invasion than the former.

The whole protocol was designed very cleverly from the start to avoid all the privacy blocks that might inhibit people from using it [1], because the main drawback in this is that it's completely useless unless you have a critical mass of users that actually use it.

It is very difficult to explain to people that are not curious about the technology and all they hear is 'tracing = tracking = no privacy'.

I imagine this is why this app has been silently pushed, but in my mind just having it available and active on phones does not help you that much if the same users are also not aware and actively reporting their infections. So you will have a very small group that consciously install it and when they get infected they report; a lot larger group will get a notification that they have been close to an infected individual. I suppose they hope that by showing those notifications then people that subsequently get tested positive will be curious enough to find out how they should report in, etc. It's risky especially seeing this backlash about silent installations...

[1] https://covid19-static.cdn-apple.com/applications/covid19/cu...

Re: Massachusetts health notifications app installed without users’ knowledge

#94

Earlier quoted context omitted.

Not exactly. On the Android store you can choose exactly which device to install an application on. For Apple as far as I know the most you can do is buy the app on desktop and, if the device is configured that way, it will receive the new app. This means it’s limited to new purchases and by the device’s settings.

Ok, but my point was that on Android and iOS it is possible to install apps without touching your phone. This qualifies as remote code execution. You need your credentials for doing this, but google and Apple apparently don't need them.

Yes, but RCE is typically shorthand for “RCE by someone other than the owner of the device”

Re: Massachusetts health notifications app installed without users’ knowledge

#95

Earlier quoted context omitted.

Read up on how the contact tracing apps work. They do not upload your data to the cloud. Phones broadcast a rolling random identifier, other phones collect received identifiers, and only on confirmed infection does the person's phone upload its last two weeks of broadcast IDs to the cloud, where other phones can grab them and cross-check. Having someone's phone number allows you (via the phone company) to trace their…

I think the low adoption is because it's hard to explain. No one on my street, none of the most vulnerable people would understand your paragraph. No wonder it's not being adopted by those who should be adopting it, but just being used by vigilant young tech savvy and already covid safe people. So not only are only a small number of people using it, these people are least likely to make a difference using it.

Edit: Surely we can come up with a more approachable explanation for less technical folks, though? Here's an attempt:

"Contact tracing respects your privacy and does not send your location to the cloud.

Instead, your phone makes up a new random name every 15 minutes and broadcasts it to nearby phones. It remembers the last two weeks of names it used, as well as the last two weeks of names it heard from other phones.

When someone catches COVID-19, they register it in the app. Their phone then uploads the last two weeks' worth of names it used to the cloud, where other phones can download the data. The names aren't connected to their identity, all they represent is someone who caught COVID-19.

If your phone finds a match between a name it has recently heard and the online database, it sends you a notification. After 2 weeks the data is erased, so you are only notified if you were near an infected person in the past 2 weeks.

Since the random names change every 15 minutes, nobody can track you or know that you are the same person as last time they saw your phone. The data is only stored locally, so after it is deleted two weeks later, there is no way to go back and recover it."

How's that?

(Edited because without the intro sentence it sounded like I was trying to imply the parent didn't get it; that wasn't my intent.

Re: Massachusetts health notifications app installed without users’ knowledge

#96

Earlier quoted context omitted.

I thought this was well-known, Android is not private at all until you degoogle. Unlock your bootloader then install a ROM without Google Play Services such as GrapheneOS, CalyxOS or LineageOS. You can consider installing microG also as an open-source minimal implementation of Google Play Services if some of it's functionality is absolutely necessary for you to keep.

That doesn't fix the issue ISPs mandate certain capabilities of the cellular modem + the simcards (remember java cards? that ran java? they still exist as simcards!) Government RCE is still 100% on the table regardless of whatever software your phone is running

The factual basis of your assertion is absolutely true, but your attitude is unhelpful and defeatist.

There is a chasm between "a state actor throws an 0day at you" and "Google remotely installs an app on your phone". The latter is done at scale. The former is expensive, risky, and used relatively rarely.

If you're organizing a protest movement, it's totally reasonable to factor government 0days into your threat model. For more boring people, running GrapheneOS is a great way to reduce the attack surface they expose to the advertising and mass surveillance industrial complex.

Re: Massachusetts health notifications app installed without users’ knowledge

#97
post #35
post #21

Earlier quoted context omitted.

> There’s nothing worrying about that. You get tons of apps installed without consent (including whatever spam your network provider pushes on you). That is different. They are pre-installed and I can list them and disable them. They do not install suddenly by themselves months after buying the device. If they did so, there would be an outrage. > This app can actually save lives without sacrificing any privacy, pushi…

> They do not install suddenly by themselves months after buying the device. If they did so, there would be an outrage. They absolute can do that, and do that. For example, if you switch SIM cards, the phone can (and in some situations will) install whatever crap the ISP chooses. In my case, inserting a SIM card from ALDI’s carrier used to auto-install some weather, news, and similar stuff. Luckily that stopped recen…

> but that’s more of a worry in 3rd-world-dictatorships

To be this delusional, it must feel great.

Re: Massachusetts health notifications app installed without users’ knowledge

#98

Earlier quoted context omitted.

I thought this was well-known, Android is not private at all until you degoogle. Unlock your bootloader then install a ROM without Google Play Services such as GrapheneOS, CalyxOS or LineageOS. You can consider installing microG also as an open-source minimal implementation of Google Play Services if some of it's functionality is absolutely necessary for you to keep.

That doesn't fix the issue ISPs mandate certain capabilities of the cellular modem + the simcards (remember java cards? that ran java? they still exist as simcards!) Government RCE is still 100% on the table regardless of whatever software your phone is running

It's hard to get good info on what capabilities it does have. Here's what I've gathered though I'd like to learn more:

Modems are often isolated by being connected via USB, or if on your SoC the modem has DMA then it's isolated via IOMMU groups.

SIM cards have to implement the E911 feature which allows 911 operators to toggle a cell phone into "stay online no matter what" mode.

Some SIM cards have additional apps installed on them, which allows attacks like SIMjacker and WIBattack.

Re: Massachusetts health notifications app installed without users’ knowledge

#99
post #96

Earlier quoted context omitted.

That doesn't fix the issue ISPs mandate certain capabilities of the cellular modem + the simcards (remember java cards? that ran java? they still exist as simcards!) Government RCE is still 100% on the table regardless of whatever software your phone is running

The factual basis of your assertion is absolutely true, but your attitude is unhelpful and defeatist. There is a chasm between "a state actor throws an 0day at you" and "Google remotely installs an app on your phone". The latter is done at scale. The former is expensive, risky, and used relatively rarely. If you're organizing a protest movement, it's totally reasonable to factor government 0days into your threat mode…

its not exactly a 0day if the ISP is communicating (through an intermediary) to a card the ISP gave you, that's just normal, unexpensive

And this is like, literally a state actor installing an app in this case?

Re: Massachusetts health notifications app installed without users’ knowledge

#100

Earlier quoted context omitted.

I think the low adoption is because it's hard to explain. No one on my street, none of the most vulnerable people would understand your paragraph. No wonder it's not being adopted by those who should be adopting it, but just being used by vigilant young tech savvy and already covid safe people. So not only are only a small number of people using it, these people are least likely to make a difference using it.

Edit: Surely we can come up with a more approachable explanation for less technical folks, though? Here's an attempt: "Contact tracing respects your privacy and does not send your location to the cloud. Instead, your phone makes up a new random name every 15 minutes and broadcasts it to nearby phones. It remembers the last two weeks of names it used, as well as the last two weeks of names it heard from other phones.…

Ahh apologies. It's not the wording of your paragraph, I understood both very well, they are well written.

It's a more fundamental understanding of stuff that's hard by those who are most at risk. The old, the vulnerable etc.

It's the old digital divide idea. My neighbor doesn't have any internet connected devices, for example. But she would benefit much more from the app than 40 of her mask wearing, young, self isolating, working from home fellow city inhabitants.

Post reply on HN