Live data from Hacker News

Analysis of SwissCovid app

lasec.epfl.ch

31–33 of 33 posts

Re: Analysis of SwissCovid app

#31
Same thing happened in Germany, UK and France. They waited until Apple/Google could provide Low Energy Bluetooth support. Earlier apps had energy problems, bit did implement the tracking ID securely, decentralized. Now the OS update the new apps don't use their own decentralized tracking anymore, they switched over to. the OS provided new "Random ID", which is a centralized Tracking ID. All those countries are lying about the security implications. In CH at least there was some public criticism which is conveniently ignored, I guess. The implication is that each government has now to ask Apple and Google via their friendly NSA contacts for the ID's in question. Which is not different from the previous protocol to get the search history or location protocol for its citizens.

Re: Analysis of SwissCovid app

#32
Nobody commenting on the (lack of) formatting? I mean, I know we techies love plain and simple markup but this looks like taking a piss at the readers.

The content is not that great and the plain text does nothing to make it feel technical coherent or valuable.

Re: Analysis of SwissCovid app

#33

> In summary, our observations are as follows. > Some servers are hosted by Amazon, as part of a CDN service. FUD - This report is all about Fear, Uncertainty and Doubt and is every bit as dangerous as lying. I find it difficult to believe that, even among the HackerNews crowd, this point registers near as important as having an easy to use, efficient way to do contact tracing for Covid-19. Why does every attempt to…

Unfortunately, I agree with this view of the report. The report does do a mid-depth technical dive and raises the sort of things a security analyst would certainly look to verify, and I will use it as a base for other app analysis - but it conflates hypothetical risks with vulnerabilities. I am dealing with these precise technical issues around de-identification and encryption in a professional context right now. The…

I agree generally with you, but Prof Vaudenay is not "out of his depth". His publication record would show that he knows the difference between key derivation and encryption. The people who don't are those trying to write the overly simplified summaries to calm people's nerves, in particular in the case of Vaudenay is taking about, the Confederation government, who should know better.
Post reply on HN