Live data from Hacker News

First look at Apple/Google contact tracing framework

twitter.com

61–70 of 113 posts

Re: First look at Apple/Google contact tracing framework

#61
post #16

An important question here is: will this framework go away once the pandemic is over? Something tells me it won't.

If no one requests the locations of positive reports and no one reports the location of positive patients, what left is there that needs to "go away"?

Seems like a pretty good system to me.

Re: First look at Apple/Google contact tracing framework

#62
post #16

An important question here is: will this framework go away once the pandemic is over? Something tells me it won't.

To ease on the fear mongering front here: This proposal relies on an app implementing these protocols, you're free to uninstall the app after the pandemic - or not install it in the first place. It is furthermore trivial to check if your device sends out these BTLE packets.

It's not a "can we put the genie back in the bottle" scenario if the genie is wearing a bright warning vest announcing its presence everywhere. You can directly measure if it's still there. All other concerns are not technical ones. If you acknowledge digital contact tracing to be a thing, this is better for privacy than any other proposal so far. The framework is designed to prevent abuse even in case it would not go away.

Re: First look at Apple/Google contact tracing framework

#63
post #32
post #16

An important question here is: will this framework go away once the pandemic is over? Something tells me it won't.

Having a standardized framework is a good thing provided it meets certain minimal security and privacy needs. The idea is to enable end users to proactively collect useful data without making the potential for government abuse any worse than it already is. So long as all data remains on the physical device at all times and any access or export is _always_ actively initiated by the user, I don't see how it makes the c…

> An abusive government can already subpoena or otherwise monitor all the network providers.

The advantage that this tracking proposal provides is that it unfurls contact tracing from one node. Until now, authorities have had to work from a large dataset ( all phones on a mast at a particular time ) inwards; now they can start with one node of interest and expand outwards.

Combined with some other 'temporary' pandemic measures, such as the legal requirement to carry your phone at all times, this provides a huge benefit to any authority.

Re: First look at Apple/Google contact tracing framework

#64

Finally a decent use-case for blockchain and nobody is paying attention. Seems to make a lot more sense to reconcile location and proximity from a shared user-controlled anonymous ledger.

There's plenty of Blockchain based proposals for the backend of this, none of which takes off because it's another one of these imaginary use cases that can just leverage existing centralisation without wasting time on solving problems the introduction of a decentralised Blockchain architecture brings with it.

Re: First look at Apple/Google contact tracing framework

#65
post #60

Again, this solution _cannot_ work and it is a _threat_ to a permanent loss of privacy. This is like the government and the adtech companies sleeping in the same bed, without any other power opposition in the balance. 1) The "solution" is created by a monopoly of 2 american private corporations. 2) It can only work reliably if everyone wear an (Apple or Android) phone at all time, and consent to give data 3) You are…

1) and 2) - the fact that Google and Apple have what is essentially a monopoly on smartphone software is exactly what makes this a good approach. it's the easiest way to reach a high percentage of the population.

3) false positive are a hell of a lot better than having no way to trace back contacts while someone was asymptomatic but contagious.

4) it helps stop others from becoming infected and possibly dying. how is that not a good thing?

> We should be 3D printing ventilators, analysing DNA sequences, build nanorobots and synthesis new molecules.

3D printing ventilators is a horrible idea, and everything else towards a vaccine takes _time_. This is something that can be rolled out today and that will help the situation. You can uninstall the app when this is over.

Re: First look at Apple/Google contact tracing framework

#66
post #60

Again, this solution _cannot_ work and it is a _threat_ to a permanent loss of privacy. This is like the government and the adtech companies sleeping in the same bed, without any other power opposition in the balance. 1) The "solution" is created by a monopoly of 2 american private corporations. 2) It can only work reliably if everyone wear an (Apple or Android) phone at all time, and consent to give data 3) You are…

1) and 2) - the fact that Google and Apple have what is essentially a monopoly on smartphone software is exactly what makes this a good approach. it's the easiest way to reach a high percentage of the population. 3) false positive are a hell of a lot better than having no way to trace back contacts while someone was asymptomatic but contagious. 4) it helps stop others from becoming infected and possibly dying. how is…

> 4) it helps stop others from becoming infected and possibly dying. how is that not a good thing?

The virus will always be here, we cannot hide forever, we must find a way to cure it or reduce its biological effect. Once covid19 goes away (if ever), and a new virus appears, NO ONE will have that app turned on, and by then, the new virus will have spread just like covid19.

I have a very simple solution to win time : total confinement of people of more than 60 years old when a new virus is detected, and wash hands.

Also check hemo2life, which is an example of what we could do in terms of medicine

Re: First look at Apple/Google contact tracing framework

#67
post #55
post #9

Note that years ago, Moxie has studied a similar problem of how to let users know if their contacts use Signal or not without uploading the whole address books like e.g. WhatsApp does [0]. It's similar because in both instances you want to "match" users in some fashion using a centralized service while keeping their privacy. He ruled out downloads of megabytes of data (something that the Google/Apple proposal would i…

Increasing the lifetime for what are currently "daily keys" reduces the precision of the contact reporting - e.g. your example of a week means that a positive user would need to report at least 3 weeks of keys, so someone can now do correlation over 3 weeks instead of X days. There's no inclusion of location data as that has no value - the only thing that this protocol cares about was whether you were in the vicinity…

I think he was trying to say you could reduce the computation by narrowing the space-time radius, then searching for matches. Even a state-level restriction would be enough to substantially narrow down the possible matches without sacrificing anonymity.

Re: First look at Apple/Google contact tracing framework

#68

Regardless of the technical issues with this, I think the "prank" issue Moxie brings up is much more serious. We've already seen the phenomenon of "Zoom bombing", I can imagine "tracer bombing" would be a much more serious issue. The only way I could see this working is that if when you enter a positive result you have to enter some sort of secret key from the testing authority, but that's totally not tenable given a…

Many of the issues moxie brings up either don't apply universally or are unrelated to the part this specification touches upon. Maybe it helps to bring up a non US perspective here: in Germany, like many other European countries, this becomes a non-issue. We have central authorities that can greenlight a positive test result or invalidate wrong results, immediately making the prank argument completely hypothetical. T…

> in Germany, like many other European countries, this becomes a non-issue.

What do you mean by that? The protocol, as published, doesn’t have a role for the central authority. Even if the German state knows that mrSick tested positive and mrPrankster did not, how would the diagnosis server reject the keys published by mrPrankster? They are by design resistant to de-anonymization. In fact the German state can’t even know if a specific key reported as positive for covid belongs to a german resident or not.

Re: First look at Apple/Google contact tracing framework

#69
post #9

Note that years ago, Moxie has studied a similar problem of how to let users know if their contacts use Signal or not without uploading the whole address books like e.g. WhatsApp does [0]. It's similar because in both instances you want to "match" users in some fashion using a centralized service while keeping their privacy. He ruled out downloads of megabytes of data (something that the Google/Apple proposal would i…

You don't need full SGX if you trust the provider.

People already trust providers with their medical data. Why not trust some computation service to do the matching? This is a moment for trustworthy institutions to create data centers and get customers by their reputation.

Combine a big market of trustworthy providers and SGX, and abuse becomes much more difficult.

Re: First look at Apple/Google contact tracing framework

#70
post #68

Earlier quoted context omitted.

Many of the issues moxie brings up either don't apply universally or are unrelated to the part this specification touches upon. Maybe it helps to bring up a non US perspective here: in Germany, like many other European countries, this becomes a non-issue. We have central authorities that can greenlight a positive test result or invalidate wrong results, immediately making the prank argument completely hypothetical. T…

> in Germany, like many other European countries, this becomes a non-issue. What do you mean by that? The protocol, as published, doesn’t have a role for the central authority. Even if the German state knows that mrSick tested positive and mrPrankster did not, how would the diagnosis server reject the keys published by mrPrankster? They are by design resistant to de-anonymization. In fact the German state can’t even…

My main point is that the protocol as published is completely unrelated to the prank scenario, that's simply out of scope. The protocol does not prescribe who is able to report certain Diagnostic Keys that have tested positive. In a centralised deployment, that is likely under the current German reporting chain for infectious diseases, mrPrankster has no capability to falsely report a positive test result. You have a trustworthy central stakeholder that can provide a ground truth. At the very least it could be designed to be revocable (a step that would be necessary for false positive test results anyway).
Post reply on HN