Earlier quoted context omitted.
I'm not sure I'd count this as fearmongering. I think I know which way the tradeoffs work in my mind but there's not an unreasonable set of paths that lead to this being more permanent. Given the broad powers passed recently in the UK they could make having this app a legal requirement to go in any shop if they wanted, and whether apps can be uninstalled reasonably is down to whoever controls the OS. Would it not mak…
> they could make having this app a legal requirement to go in any shop if they wanted If they can legally mandate an "app" they can mandate me having a device to run said "app". It'd be absolutely absurd to mandate you having a spy with you at all times to exist in society. "Sorry, don't have a phone, kthx", "Sorry, my phone doesn't use gapps, it's using a custom ROM", and what about these Linux phones? Yeah, that's…
First look at Apple/Google contact tracing framework
101–110 of 113 posts
Re: First look at Apple/Google contact tracing framework
#102Yikes, this is prep for big brother's guilt by association. I wouldn't want to test positive for anything the state can track (radical ideas? you're now a positive in this system). Opt out.
Or, it's just what it says. It's a way to implement test and trace, something that is absolutely needed to stop a pandemic like this from killing hundreds of thousands if not millions of people. Everything isn't a slippy slope. Everything isn't about your privacy. Everything isn't a grand conspiracy that only you can see and the sheeple are too dumb to understand. Sometimes, extreme measures are needed.
Crises are often used by despots to seize power. That's not a conspiracy, that's historical fact. In the United States, we've seen it recently - 9/11 was used to degrade our rights across a large number of issues, and we've never gotten them back.
Implementing systems to track everyone people come into contact with is absolutely a huge invasion of privacy, and obviously not necessary.
> Sometimes, extreme measures are needed.
Extreme times do not justify all extreme measures.
Every time you lose rights or privacy, assume it's permanent. Our government is not suited for repealing law.
Re: First look at Apple/Google contact tracing framework
#103Earlier quoted context omitted.
The proposed system requires download of 16 bytes per infected user per day. Unless this really gets out of hand that’s not in the megabytes range.
Yes, this is where OP lost me. > Published keys are 16 bytes, one for each day. If moderate numbers of smartphone users are infected in any given week, that's 100s of MBs for all phones to DL. "Moderate" rate of infections is not millions of new cases per week worldwide. That would be such a catastrophe that contact tracing would be useless.
If more cases would be tested in India or Africa or Sputh America a ten fold increase wouldn’t be unthinkable.
Re: First look at Apple/Google contact tracing framework
#104Earlier quoted context omitted.
Or, it's just what it says. It's a way to implement test and trace, something that is absolutely needed to stop a pandemic like this from killing hundreds of thousands if not millions of people. Everything isn't a slippy slope. Everything isn't about your privacy. Everything isn't a grand conspiracy that only you can see and the sheeple are too dumb to understand. Sometimes, extreme measures are needed.
> Everything isn't a slippy slope. Everything isn't about your privacy. Everything isn't a grand conspiracy that only you can see and the sheeple are too dumb to understand. Crises are often used by despots to seize power. That's not a conspiracy, that's historical fact. In the United States, we've seen it recently - 9/11 was used to degrade our rights across a large number of issues, and we've never gotten them back…
Re: First look at Apple/Google contact tracing framework
#105> So first obvious caveat is that this is "private" (or at least not worse than BTLE), until the moment you test positive. > At that point all of your BTLE mac addrs over the previous period become linkable. Linkable over the period of 14 days. Or even linkable during one day - each day means new key, so linking between these might be attempted only on basis on behavioral correlations. What to do with such data? Micr…
Re: First look at Apple/Google contact tracing framework
#106Again, this solution _cannot_ work and it is a _threat_ to a permanent loss of privacy. This is like the government and the adtech companies sleeping in the same bed, without any other power opposition in the balance. 1) The "solution" is created by a monopoly of 2 american private corporations. 2) It can only work reliably if everyone wear an (Apple or Android) phone at all time, and consent to give data 3) You are…
From looking at the specification, I don't see any serious loss of privacy there, if this is implemented as stated. 2) You don't need 100%, you only need enough to drop the R0 below 1. You'll likely need a majority of people using this, which is hard enough, but you don't need everyone using it. 3) The apps are not supposed to include every single registered contact, only contacts that are over a bit longer timeframe…
It's going to be built into iOS and Android at the operating system level, and I assume have a very clear prompt to opt-in. It would not surprise me if it quickly reaches >50% of active users, at least for iOS.
Getting a timely Android update on the other hand...
Re: First look at Apple/Google contact tracing framework
#107Let's just answer these * Use stationary beacons to track someone’s travel path Doesn't work because there's no externally visible correlation between reported identifiers until after the user chooses to report there test result. * Increased hit rate of stationary / marketing beacons Doesn't work because they depend on coherence in the beacons, and the identifiers roll every 10 or so minutes. Presumably you'd ensure…
> Doesn't work because there's no externally visible correlation between reported identifiers until after the user chooses to report there test result. So you're saying it works after the user reports their test result.
To be very very clear
* The only things published by someone when they report a positive test result are the day keys for whatever length of time is reasonable (I assume ~14 days?)
* Given those day keys it is possible for your device to generate all the identifiers that the reporter's device would have broadcast.
* From that they can go through their database of seen identifiers and see if they find a match.
That means your device can determine when you were in proximity to the reporter, so it would in theory be able to know approximately where the contact happened, but you can't determine anything beyond that.
The server that collects and serves reported day keys doesn't have the list of identifiers any devices have encountered, so it can't learn anything about the reporters from the day keys they upload.
Let's say there's a passive fixed beacon (whatever) in a public space, it can't connect the identifiers to any specific device either, but you could see it being a useful public health tool - "we saw carriers at [some park] at [some times]". It still would not know which specific devices were reporting those keys. Even if that device went through after the day keys were published there's no way to know that its a device that's been seen before.
Only the server is able to link published day keys together because it receives them, so presumably knows who published those. The spec explicitly disallows an implementation from doing this, but assumes a malicious server, so it works to ensure that the only information it can get are day keys with no other information.
Re: First look at Apple/Google contact tracing framework
#108Earlier quoted context omitted.
Why use a centralized model? Allow users to subscribe to a data source so that any entity can push their own dataset. This is also important because it keeps the framework usable under a variety of adverse and unusual circumstances. An aid organization operating in a disaster zone or impoverished area could make use of such a framework without needing permission from a higher authority or even reliable internet acces…
Because it can abused. The easier you make it upload, it also allows bad actors to upload invalid data to cause people to go into quarantine unnecessarily. It only works well if you can trust the data, so I think it should error on the side of validating the data instead of openness.
Re: First look at Apple/Google contact tracing framework
#109Earlier quoted context omitted.
Having a standardized framework is a good thing provided it meets certain minimal security and privacy needs. The idea is to enable end users to proactively collect useful data without making the potential for government abuse any worse than it already is. So long as all data remains on the physical device at all times and any access or export is _always_ actively initiated by the user, I don't see how it makes the c…
> An abusive government can already subpoena or otherwise monitor all the network providers. The advantage that this tracking proposal provides is that it unfurls contact tracing from one node. Until now, authorities have had to work from a large dataset ( all phones on a mast at a particular time ) inwards; now they can start with one node of interest and expand outwards. Combined with some other 'temporary' pandemi…
In such a hypothetical scenario, how is making this (currently opt-in) framework mandatory any different from requiring you to install a government provided app? Such a government app could trivially log sensor and GPS data, yielding a _far_ more detailed view. The point is that the mere existence of this framework doesn't make the situation any worse than it already is.
Re: First look at Apple/Google contact tracing framework
#110Earlier quoted context omitted.
Yes, this is where OP lost me. > Published keys are 16 bytes, one for each day. If moderate numbers of smartphone users are infected in any given week, that's 100s of MBs for all phones to DL. "Moderate" rate of infections is not millions of new cases per week worldwide. That would be such a catastrophe that contact tracing would be useless.
Currently there are 1.2 million active infections. Doesn’t this mean every smartphone in the world would need to download 17 MB per day? If more cases would be tested in India or Africa or Sputh America a ten fold increase wouldn’t be unthinkable.