Live data from Hacker News

First look at Apple/Google contact tracing framework

twitter.com

111–113 of 113 posts

Re: First look at Apple/Google contact tracing framework

#111
post #103

Earlier quoted context omitted.

Yes, this is where OP lost me. > Published keys are 16 bytes, one for each day. If moderate numbers of smartphone users are infected in any given week, that's 100s of MBs for all phones to DL. "Moderate" rate of infections is not millions of new cases per week worldwide. That would be such a catastrophe that contact tracing would be useless.

Currently there are 1.2 million active infections. Doesn’t this mean every smartphone in the world would need to download 17 MB per day? If more cases would be tested in India or Africa or Sputh America a ten fold increase wouldn’t be unthinkable.

No, my understanding is you only would download two weeks worth of keys when a new infection is reported. There is an assumption in any method of contact tracing that once people test positive that they are isolating themselves. If they don't, there is no reason to do the tracing since the virus will simply spread exponentially.

Re: First look at Apple/Google contact tracing framework

#112
post #107

Earlier quoted context omitted.

> Doesn't work because there's no externally visible correlation between reported identifiers until after the user chooses to report there test result. So you're saying it works after the user reports their test result.

I'm not sure what you're saying "works" here. To be very very clear * The only things published by someone when they report a positive test result are the day keys for whatever length of time is reasonable (I assume ~14 days?) * Given those day keys it is possible for your device to generate all the identifiers that the reporter's device would have broadcast. * From that they can go through their database of seen ide…

It is pretty clear that a single piece of data gathered by this system is fairly useless. But the more data an entity has gathered, the better it can be used to paint a whole picture.

If the server is malicious (think a government doing surveillance), it is possible that the data from passive fixed beacons gets linked with the identity of the person uploading keys, via IP address (when keys are uploaded) or facial recognition gathered by cameras next to Bluetooth receivers. This data can also be linked with data from fixed beacons in other places, which would allow for tracking someone throughout a variety of places.

Re: First look at Apple/Google contact tracing framework

#113
post #87

Earlier quoted context omitted.

1) and 2) - the fact that Google and Apple have what is essentially a monopoly on smartphone software is exactly what makes this a good approach. it's the easiest way to reach a high percentage of the population. 3) false positive are a hell of a lot better than having no way to trace back contacts while someone was asymptomatic but contagious. 4) it helps stop others from becoming infected and possibly dying. how is…

As both are untrustworthy American corporations no matter what they do or say it will always be a huge privacy issue. I would go back to my old SE810i phone the instant this was forced on iOS and Android users. People are already doing this (especially young people) so this will be apple and google shooting themselves in the foot.

I mean, yes, they are evil untrustworthy American corporations, but _they_ already know where you are and who you've met.
Post reply on HN