Google and Apple Plan to Turn Phones into COVID-19 Contact-Tracking Devices

DDE_Server

Level 22
Thread author
Verified
Top Poster
Well-known
Sep 5, 2017
1,168
Tech giants Apple and Google have joined forces to develop an interoperable contract-tracing tool that will help individuals determine if they have come in contact with someone infected with COVID-19.
As part of this new initiative, the companies are expected to release an API that public agencies can integrate into their apps. The next iteration will be a built-in system-level platform that uses Bluetooth low energy (BLE) beacons to allow for contact tracing on an opt-in basis.
The APIs are expected to be available mid-May for Android and iOS, with the broader contact tracing system set to roll out "in the coming months."

"Privacy, transparency, and consent are of utmost importance in this effort, and we look forward to building this functionality in consultation with interested stakeholders," the companies said.

The rare collaboration comes as governments worldwide are increasingly turning to technology such as phone tracking and facial recognition to battle the virus and contain the coronavirus outbreak.


Both Apple and Google have emphasized that users will have to provide their explicit consent for it to work. This also means that for it to be effective, millions of people would need to opt-in, necessitating that Apple and Google build adequate privacy safeguards before it's rolled out to the masses.

According to a white paper released by Google, here's how such a system might work:

  1. When two people come in close contact for a certain period of time (say 10 minutes or more), their phones will exchange anonymous identifier beacons. The identifiers rotate every 15 minutes and have no personally identifiable information.
  2. If one of the two is positively diagnosed for COVID-19, that infected person can enter the test result into an app from a public health authority that has integrated the aforementioned API.
  3. Then, the infected person can consent to upload the last 14 days of his or her broadcast beacons to the system.
  4. Any other person who has been in close proximity to the individual tested positive will then be alerted if there exists a beacon on the device that matches the broadcast beacons of everyone who has tested positive for COVID-19 in the region.
  5. The app then provides the individual with information about the next steps.

"This model places less trust in a central authority, but it creates new risks to users who share their infection status that must be mitigated or accepted," the Electronic Frontier Foundation (EFF) said about the proposal.

"Full transparency about how the apps and the APIs operate, including open source code, is necessary for people to understand, and give their informed consent to the risks," it added.

Apple and Google's system is along the lines of TraceTogether, an app developed by Singapore government officials to enable contact tracing via Bluetooth.
 

Parsh

Level 25
Verified
Honorary Member
Top Poster
Malware Hunter
Well-known
Dec 27, 2016
1,480
In my country, Govt has launched an app, again based on GPS and Bluetooth. It forms social graphs and could alert you if you've crossed paths with an infected person... followed by self-isolation instructions and official support details (1)(2).
Earlier, they'd launched another app that claimed to also help test breathing capacity. Not sure if it was meant to use sensors to check the oxygen saturation or was vaguely based on surveying. The app has been replaced though.
"This model places less trust in a central authority, but it creates new risks to users who share their infection status that must be mitigated or accepted," the Electronic Frontier Foundation (EFF) said about the proposal.
This is a very important point - highlighting the chances of choice/responsibility - an infected person may or may not take to share the details. And that only actually infected people feed positive to the app. And this applies to other apps following a similar model.
 

Stopspying

Level 19
Verified
Top Poster
Well-known
Jan 21, 2018
814
The EFF questions whether this system will work and how it might compromise the privacy of users.


The Threatpost take on the EFF report -
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top