TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

First look at Apple/Google contact tracing framework

208 pointsby dmvaldmanabout 5 years ago

20 comments

est31about 5 years ago
Note that years ago, Moxie has studied a similar problem of how to let users know if their contacts use Signal or not without uploading the whole address books like e.g. WhatsApp does [0]. It&#x27;s similar because in both instances you want to &quot;match&quot; users in some fashion using a centralized service while keeping their privacy.<p>He ruled out downloads of megabytes of data (something that the Google&#x2F;Apple proposal would imply) and couldn&#x27;t find a good solution beyond trusting Intel&#x27;s SGX technology, arguably not really a good solution but better than not adopting it at all [1].<p>You have kind of a computation&#x2F;download&#x2F;privacy tradeoff here. You can increase the time interval of the daily keys to weeks. Gives you less stuff to download but the devices have to do more hashes to verify whether they have been in contact with other devices. You can increase the 10 minutes to an hour. That means less privacy and more trackability, but also less computation needed.<p>My guess to why Google&#x2F;Apple didn&#x27;t introduce rough location (like US state or county) into the system was to prevent journalists from jumping onto that detail and sensationalizing it into something it isn&#x27;t (Google&#x2F;Apple grabbing your data). Both companies operate the most popular maps apps on the planet as well as OS level location services that phone home constantly so they are already in possession of that data.<p>[0]: <a href="https:&#x2F;&#x2F;signal.org&#x2F;blog&#x2F;contact-discovery&#x2F;" rel="nofollow">https:&#x2F;&#x2F;signal.org&#x2F;blog&#x2F;contact-discovery&#x2F;</a><p>[1]: <a href="https:&#x2F;&#x2F;signal.org&#x2F;blog&#x2F;private-contact-discovery&#x2F;" rel="nofollow">https:&#x2F;&#x2F;signal.org&#x2F;blog&#x2F;private-contact-discovery&#x2F;</a>
评论 #22839873 未加载
评论 #22840310 未加载
评论 #22838865 未加载
评论 #22840651 未加载
hn_throwaway_99about 5 years ago
Regardless of the technical issues with this, I think the &quot;prank&quot; issue Moxie brings up is much more serious. We&#x27;ve already seen the phenomenon of &quot;Zoom bombing&quot;, I can imagine &quot;tracer bombing&quot; would be a much more serious issue. The only way I could see this working is that if when you enter a positive result you have to enter some sort of secret key from the testing authority, but that&#x27;s totally not tenable given a lot (most?) testing these days is from private providers.
评论 #22839234 未加载
评论 #22840657 未加载
评论 #22839126 未加载
评论 #22839067 未加载
评论 #22840055 未加载
评论 #22839188 未加载
评论 #22839883 未加载
krczabout 5 years ago
&gt; So first obvious caveat is that this is &quot;private&quot; (or at least not worse than BTLE), <i>until</i> the moment you test positive. &gt; At that point all of your BTLE mac addrs over the previous period become linkable.<p>Linkable over the period of 14 days. Or even linkable during one day - each day means new key, so linking between these might be attempted only on basis on behavioral correlations.<p>What to do with such data? Microanalysis of customer behaviors? It won&#x27;t be possible to use such data for future customer profiling, as it won&#x27;t be possible to match the history with identifiers after the infection. This data is practically worthless.
评论 #22844855 未加载
olliejabout 5 years ago
Let&#x27;s just answer these<p>* Use stationary beacons to track someone’s travel path<p>Doesn&#x27;t work because there&#x27;s no externally visible correlation between reported identifiers until after the user chooses to report there test result.<p>* Increased hit rate of stationary &#x2F; marketing beacons<p>Doesn&#x27;t work because they depend on coherence in the beacons, and the identifiers roll every 10 or so minutes. Presumably you&#x27;d ensure that any rolling of the bluetooth MAC also rolls the reported identifier.<p>* Leakage of information when someone isn’t sick<p>The requests for data simply tell you someone is using an app - which you can already tell if they&#x27;re using app.<p>The system can encourage someone to get tested, if your app wants to tell people to get tested, then FairPlay to that app (though good luck in the US).<p>- Fraud resistance<p>Not a privacy&#x2F;tracking concern, though I&#x27;m sure devs will have to do something to limit spam&#x2F;dos
评论 #22841479 未加载
antplsabout 5 years ago
Again, this solution _cannot_ work and it is a _threat_ to a permanent loss of privacy.<p>This is like the government and the adtech companies sleeping in the same bed, without any other power opposition in the balance.<p>1) The &quot;solution&quot; is created by a monopoly of 2 american private corporations.<p>2) It can only work reliably if everyone wear an (Apple or Android) phone at all time, and consent to give data<p>3) You are not necessarily infected if you cross an infected in the street at 5 meters. This will have too many false positives and give fuzzy information to people<p>4) It doesn&#x27;t help people who are infected and _dying_<p>It just _doesnt make sense_. To me, it looks like electronic voting, but worse. No one can understand how it works, beside experts.<p>Today it is reviewed, but then the app will be forgotten and updated in the background with &quot;new features&quot; for adtech.<p>We are forgetting what we are fighting : a biological virus. All effort should go toward understanding the biological machinery of the virus and the hosts, in order to _cure_ the virus. We should be 3D printing ventilators, analysing DNA sequences, build nanorobots and synthesis new molecules.
评论 #22840688 未加载
评论 #22840641 未加载
评论 #22840220 未加载
评论 #22840707 未加载
Reelinabout 5 years ago
Is there an official document somewhere?<p>Also, how does it compare to DP-3T? (<a href="https:&#x2F;&#x2F;github.com&#x2F;DP-3T&#x2F;documents" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;DP-3T&#x2F;documents</a>) (<a href="https:&#x2F;&#x2F;ncase.me&#x2F;contact-tracing&#x2F;" rel="nofollow">https:&#x2F;&#x2F;ncase.me&#x2F;contact-tracing&#x2F;</a>)<p>Edit: Apple&#x27;s preliminary specification was linked in another HN comment. (<a href="https:&#x2F;&#x2F;covid19-static.cdn-apple.com&#x2F;applications&#x2F;covid19&#x2F;current&#x2F;static&#x2F;contact-tracing&#x2F;pdf&#x2F;ContactTracing-CryptographySpecification.pdf" rel="nofollow">https:&#x2F;&#x2F;covid19-static.cdn-apple.com&#x2F;applications&#x2F;covid19&#x2F;cu...</a>)
评论 #22840008 未加载
pferdeabout 5 years ago
What&#x27;s it with people making long, split-up twitter threads like this? They&#x27;re cumbersome and hard to read. Be an adult, write and publish an article on your blog.<p>It feels weird having to criticize Marlinspike about this, but stupid practices are stupid no matter how prestigious the person doing them is.
评论 #22842036 未加载
femto113about 5 years ago
The system doesn&#x27;t need to ship every key to every phone, much more compact structures like Bloom filters could be used instead. If we assume about 1000 positives per day and each positive uploading 14 days of keys at 4 keys per hour that&#x27;s a bit over 1 million keys per day. A Bloom filter with a false positive rate of 1&#x2F;1000 could store that in about a megabyte. Phone downloads the filter each day and checks its observed keys, and only needs to download the actual keys if there&#x27;s a potential match.
评论 #22839235 未加载
评论 #22839169 未加载
评论 #22839184 未加载
zeckalphaabout 5 years ago
&gt; Published keys are 16 bytes, one for each day. If moderate numbers of smartphone users are infected in any given week, that&#x27;s 100s of MBs for all phones to DL.<p>Seems like a usecase for bloom filters or k-anonymity.
评论 #22839629 未加载
评论 #22839521 未加载
评论 #22839478 未加载
daenzabout 5 years ago
An important question here is: will this framework go away once the pandemic is over? Something tells me it won&#x27;t.
评论 #22840093 未加载
评论 #22840082 未加载
评论 #22839193 未加载
评论 #22839200 未加载
评论 #22841348 未加载
评论 #22839128 未加载
评论 #22839119 未加载
severineabout 5 years ago
<a href="https:&#x2F;&#x2F;threadreaderapp.com&#x2F;thread&#x2F;1248707315626201088.html" rel="nofollow">https:&#x2F;&#x2F;threadreaderapp.com&#x2F;thread&#x2F;1248707315626201088.html</a>
评论 #22838792 未加载
grumpleabout 5 years ago
Yikes, this is prep for big brother&#x27;s guilt by association. I wouldn&#x27;t want to test positive for anything the state can track (radical ideas? you&#x27;re now a positive in this system). Opt out.
评论 #22841342 未加载
themarkabout 5 years ago
Seems like a lot of processing. I wonder how much battery performance will be affected.
komeabout 5 years ago
that&#x27;s the new electronic voting: making easy stuff more complicated and dangerous...<p>the problem is not not a technological problem, it&#x27;s a political problem.
bobowzkiabout 5 years ago
Goodbye last shred of privacy.<p>&quot;The road to hell is paved with good intentions&quot; is an expression that comes to mind.
redis_mlcabout 5 years ago
Can somebody address the issue that we have almost no testing ability in the US?
评论 #22838788 未加载
评论 #22839177 未加载
Zenbit_UXabout 5 years ago
No clue who&#x2F;what a moxie is (presumably some guy) and it makes this threads title seem even more absurd.<p>OP feeling like we all need to know what moxie thinks about this reminds me of this [Chappelle Show skit](<a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=Mo-ddYhXAZc" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=Mo-ddYhXAZc</a>) about getting Ja Rule&#x27;s hot take on current events.
评论 #22838413 未加载
mc32about 5 years ago
Of course Google promises [1]:<p>“ adhering to our stringent privacy protocols and protecting people&#x27;s privacy. No personally identifiable information, such as an individual&#x27;s location, contacts or movement, will be made available at any point.&quot;<p>[1] <a href="https:&#x2F;&#x2F;turnto10.com&#x2F;news&#x2F;local&#x2F;privacy-advocates-raise-concerns-about-googles-mobility-report" rel="nofollow">https:&#x2F;&#x2F;turnto10.com&#x2F;news&#x2F;local&#x2F;privacy-advocates-raise-conc...</a>
howmayiannoyyouabout 5 years ago
Finally a decent use-case for blockchain and nobody is paying attention. Seems to make a lot more sense to reconcile location and proximity from a shared user-controlled anonymous ledger.
评论 #22840105 未加载
Uhhrrrabout 5 years ago
A modest proposal: since almost everyone is going to get this and a much smaller percentage is vulnerable, perhaps we should just use this system to track those who choose to register as vulnerable.