Live data from Hacker News

Massachusetts health notifications app installed without users’ knowledge

play.google.com

181–190 of 407 posts

Re: Massachusetts health notifications app installed without users’ knowledge

#181
post #69
post #37

I think the real question is what mechanism allows them to push a random app to some phones? google play services is actively listening for remote installation requests? that's essentially a remote-code-execution backdoor to all android phones?

A corollary of your question. If Google can lawfully install arbitrary apps on ordinary users' phones, can it also run arbitrary code on the personal devices of government officials investigating it for price fixing in the ad market?

> personal devices of government officials investigating it for price fixing

Anything in the name of "improving our services".

Re: Massachusetts health notifications app installed without users’ knowledge

#182
post #69

Earlier quoted context omitted.

A corollary of your question. If Google can lawfully install arbitrary apps on ordinary users' phones, can it also run arbitrary code on the personal devices of government officials investigating it for price fixing in the ad market?

"Arbitrary" is doing a lot of sneaky work here. You're implying that the law would somehow allow Google to manipulate investigators. But the law has broad allowances and exceptions in lots of areas, and competing permissions/denials that together weave specific allowances. There's little reason to think that the law couldn't allow app installation in general and also disallow either targeting of individuals or collec…

>You're implying that the law would somehow allow Google to manipulate investigators.

Not the law. Google having root access on 2.5 billion android devices.

The law didn't allow Uber to greyball either. It did though.

This is a risk Google fully recognizes - it's why Google prevents f droid from updating apps one by one without user input. That's a privilege reserved exclusively for google play services.

Re: Massachusetts health notifications app installed without users’ knowledge

#183

People are scared of the privacy implications of tracking. They should be, but they don’t have to be. If I had any ability to execute ideas I would have made the app using raffle / cloakroom tickets as the metaphor. Every time your phone sees another phone, they get one of your tickets and you get one of theirs. Then whenever someone gets symptoms, if their ticket book was pink then the government announces “anyone w…

> Every time your phone sees another phone, they get one of your tickets and you get one of theirs.

This is exactly how the German app works. It broadcasts anonymous Bluetooth beacons, and logs whatever beacons it saw.

If you are infected, your app sends to the server "I saw these beacons then found out I'm infected", and the server updates its live infection list.

The one in Play Store uses Google Exposure Notification Framework of course, but a de-Googled version is on F-Droid: https://f-droid.org/packages/de.corona.tracing/

Re: Massachusetts health notifications app installed without users’ knowledge

#185

Most of the comments on that app as well as here are probably wrong. I'd suspect that everyone who had the app "installed without their permission" opted into the Android COVID-19 Exposure Notification program. This was deployed by Google as part of an update to Google Play Services. When you go to your phone's settings with this update, there's an option to enable COVID-19 Exposure Notifications. When you turn it on…

I'm a MA resident and this app was on my (Android) phone...until a few minutes ago when I read about it on Hacker News, found it, and deleted it. I have no memory of ever opting into the program you describe, and it isn't the type of thing I would normally do. It's possible I guess. In any case, the way they did this is creepy. There was no icon for the app; I had to look in Settings/Apps & Notifications to find it.…

MA resident as well, what worries me more is that someone thought that this method of installation was a good idea and even more worrying is that they were also able to execute on it. It feels rather shady and nefarious the lack of public announcement on it. Shenanigans like this how you get the populace to trust the local government less, which is the last thing this country needs.

Re: Massachusetts health notifications app installed without users’ knowledge

#186

Most of the comments on that app as well as here are probably wrong. I'd suspect that everyone who had the app "installed without their permission" opted into the Android COVID-19 Exposure Notification program. This was deployed by Google as part of an update to Google Play Services. When you go to your phone's settings with this update, there's an option to enable COVID-19 Exposure Notifications. When you turn it on…

I have no memory of opting in to this, but it was installed on my phone.

Updated to add: well I'll be, an hour after this comment and seeing the link show me that Mass Notification was installed, I was prompted to opt-in appropos of nothing.

Re: Massachusetts health notifications app installed without users’ knowledge

#187
post #79

It is obvious that we need better legislation to deal with all the new possibilities that technologies have opened. The installation of this app, even done with good intent, open a lot of questions on what should be possible or not to be done by government and corporations. When you get a device with pre-installed, uninstallable, or auto-installed apps. What are the rules? > "By enabling this service, you can be quic…

> In this case it seems that the same goal could have been better achieved by SMS that do not depend on the brand of your phone. The dependency on proprietary app stores and OSs seems a risk for the continuation of a free and reliable communications. While installing an app without users consent can be as questionable as you want, the point about these apps are not the notifications itself but about the contact traci…

> having a person phone number can lead to eventually identify that person while that internal trace id it might use, won't.

What? Many many bad people seem to somehow have my number. Practically daily I get an SMSs saying "I've been transferred $5000 to the please login to confirm your transaction .." or some such. I block but they keep on coming. Now, I think I'd rather the person who was responsible for these SMSs to have my phone number than a freaking app running on my phone, especially an app that was basically snuck on without consent.

Re: Massachusetts health notifications app installed without users’ knowledge

#188
post #144
post #118

Earlier quoted context omitted.

> instead of the silent install the government could have spend money in advertisement campaigns This absolutely does not work. Here, the NL gov tried this and almost nobody installed the app, despite it using the privacy-safe google/apple API.

I'm not from NL, but I am someone that did not install the COVID tracing app that our government provided (for voluntary installation). My reason was that I was not convinced by the PR that it is actually privacy safe. Just repeating "it uses a safe API, trust us/Google/Apple" was not enough for me. The subcontractor that made the app did dump some source code on GitHub saying "see, we have nothing to hide". However…

People here are downvoting you, but you were 100% right to doubt:

https://www.iccl.ie/news/serious-privacy-and-data-harvesting...

An excerpt:

> While Android users can, in theory, opt to turn off Google Play Services, users of the Covid-19 contact-tracing app in Ireland cannot turn the surveillance off if they want the contact-tracing app to work. This means the collection and use of this data is unavoidable for people who wish to use the app.

> The data shared includes long-term, unchangeable identifiers of the phone users, including their phone’s IP address, WiFi MAC address, International Mobile Equipment Identity (IMEI) number, SIM serial number, phone number and Gmail address, as well as fine-grained data from other, potentially sensitive apps, such as banking, dating or health apps. This is data which, when considered together, has the potential to draw a very detailed map of our lives and activities.

This story was posted to HN last year, and received a tiny fraction of the upvotes of the story promoting the Irish / Google / Apple app's privacy features. Which would explain why you are downvoted, despite having been proven correct well over a year ago.

Re: Massachusetts health notifications app installed without users’ knowledge

#189

Most of the comments on that app as well as here are probably wrong. I'd suspect that everyone who had the app "installed without their permission" opted into the Android COVID-19 Exposure Notification program. This was deployed by Google as part of an update to Google Play Services. When you go to your phone's settings with this update, there's an option to enable COVID-19 Exposure Notifications. When you turn it on…

I'm a MA resident and this app was on my (Android) phone...until a few minutes ago when I read about it on Hacker News, found it, and deleted it. I have no memory of ever opting into the program you describe, and it isn't the type of thing I would normally do. It's possible I guess. In any case, the way they did this is creepy. There was no icon for the app; I had to look in Settings/Apps & Notifications to find it.…

> In any case, the way they did this is creepy. There was no icon for the app; I had to look in Settings/Apps & Notifications to find it. And neither the official state press releases nor the few local news stories about it mention that the app was installed without notice. They use vague, lawyerly language about how it can be "enabled".

This incident and your comment reminded me of a story Bezos mentioned in his interview about the time Amazon deleted 1984 from kindle. The analogy he made makes me wonder how can we compare what happened here to what Amazon did..

“Without any notice or warning just electronically go into everybody’s Kindle, who had downloaded the book and just disappear it…so it would be as if we walked into your bedroom in the middle of the night, found your bookshelf, and just took that book away”

19:48 https://youtu.be/SCpgKvZB_VQ

Re: Massachusetts health notifications app installed without users’ knowledge

#190
post #180

Earlier quoted context omitted.

Virtually every non-trivial Android application has these permissions, none of which are even important enough for the system to prompt you for permission. The only interesting one is "pair with Bluetooth devices" which is how the Exposure Notifications system works.

"full network access" is a hugely important permission. My cynical side believes that the reason for it not being as visible as other permissions is that platforms profit from the ad-driven app model, which itself heavily relies on an apps ability to access the internet. That could also be why stock roms do not allow users to disable full network access on a per app basis. (...like, for example, the camera permission…

It's actually not disableable because there are so many ways to bypass it.

For example, just trick a user into clicking a hyperlink to another app like a browser which does have full internet access, and you have successfully exfiltrated any data in the URL.

Post reply on HN