Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Is much known about the log submission if someone tests positive? #7

Open
oldpec opened this issue May 6, 2020 · 0 comments
Open

Comments

@oldpec
Copy link

oldpec commented May 6, 2020

It seems to me that a lot of the potentially problematic information collected probably has a legitimate justification, ie:

  • timestamps (to work out length of contact)
  • phone models (for distance modelling, which probably needs to be done on a central server as the modeling will probably need to be adjusted over time, potentially retroactively).

However it seems to me that the log could theoretically be submitted without any reference to the user sending it, ie it might leak information about "someones" day (or if broken up, as parts of possibly several "someones" days), but not be directly linked to the person submitting?

I suppose with infection rates as low as they are in Australia that probably limits the ability to effectively anonymise the data as few people will actually be be submitting it. The upside to that is that it also means it wouldn't be an effective tool for general state surveillance....

Would there be value in an "Easy Wins" section?
Things like:

  • increasing the frequency of ID rotation
  • creating a symmetric key on ID rotation, sending it to the central server and encrypting the phone version sent in the public bluetooth beacon

seem like they would bring privacy improvements without requiring significant changes to the system design.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant