Hacker News new | ask | show | jobs
by robjan 2260 days ago
TraceTogether[1] by the Singapore government meets most of these requirements and is/will be open sourced soon.

1: https://www.tracetogether.gov.sg

4 comments

The rki (they are the ones tracking Infektion Numbers etc here in germany) is apperently Building an App based on Trace Together. This (german) article says TraceTogether is linked to your phone number though https://www.golem.de/news/corona-app-per-bluetooth-kontaktpe...
Someone did an analysis on the app and posted on reddit[1]. Turns out they included a gov analytics tracker[2] in the app

1: https://splira.com/2020-03-28/

2: https://wogaa.sg/home/index.html#/

This effectively puts proximity data in the hands of the government, violating points 3, 5, 7, 8, and 9.

> When you are close to another phone running TraceTogether, both phones use Bluetooth to exchange a Temporary ID. This Temporary ID is generated by encrypting the User ID with a private key held by the Ministry of Health (MOH).

From: https://www.tracetogether.gov.sg/common/privacystatement

In this case, even if it only does exactly what it says it does, the data gathered is more valuable than anything else. Complete movement profiles of an entire nation. Can you put a price tsg on that?

From that perspective whether it is open source is a secondary consideration.

Everyone generates an anonymous ID, if they come within Bluetooth proximity the devices trade these anonymous IDs. No location data is collected and none of the data is sent over the internet.

If you become infected you have the option of broadcasting your ID as being infected and others can compare the infected list against the IDs collected on their phones.

None of the data you mentioned is being collected.

Hmm, does that anonymous ID change? If not, it is not going to stay anonymous for very long as patterns will remain largely unchanged. People do tend to be creatures of habit.

I mentioned location data and if there is one thing we have learned over the past decade or so, it is that location is not gathered just from GPS ( which is the argument I assume you were making ).

edit: As for the claim, no data is sent over the internet.. I just plainly do not believe that statement. I do not understand how anyone would.

The app does not use GPS or other location data, contacts are established only by Bluetooth pairing.
Call me a cynic, but if apps like these became popular, I'd expect to see a creeping escalation. Reel in a large user base, then slowly capture and send more data. The possibility of being able to track a nation in real-time would have the security services blowing a load in their proverbial pants.