TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Vietnam's contact tracing app broadcasting a fixed ID

107 pointsby cryptbeabout 5 years ago

6 comments

lihopabout 5 years ago
The app is open source now: <a href="https:&#x2F;&#x2F;github.com&#x2F;BluezoneGlobal&#x2F;bluezone-app" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;BluezoneGlobal&#x2F;bluezone-app</a>. The id generation code is in this library: <a href="https:&#x2F;&#x2F;github.com&#x2F;BluezoneGlobal&#x2F;react-native-bluetooth-scan" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;BluezoneGlobal&#x2F;react-native-bluetooth-sca...</a>
meotimdihiaabout 5 years ago
Vietnamese here, no one in Vietnam cares about this app. Hence the creator also doesn&#x27;t care about app security.
评论 #22998276 未加载
serfabout 5 years ago
deleted in the interest of a fellow hacker.
评论 #22990666 未加载
dkdk8283about 5 years ago
Contract tracing is a disaster. I’ve secured a forensic RF shielding bag for my phone. I refuse to participate
评论 #22991457 未加载
moneysakeabout 5 years ago
Very interesting
cryptbeabout 5 years ago
Author here. One interesting aspect that I&#x27;ve learned is the tactics, techniques, and procedures (TTPs) of public opinion brigades, aka Force 47.<p>They tried hard to discrete me. My initial report had an error, that is I didn&#x27;t know that Bluetooth on Android needs ACCESS_FINE_LOCATION permission. A person pointed this out in a comment -- he posted and rewrote it three times. I said thank you and thought that&#x27;s that, but then he and a bunch of new people commented that since I made that basic mistake I&#x27;m immature and inexperienced, therefore the rest of my findings have no merit.<p>Someone then posted a super long comment, raising a lot of questions about my credibility and intention. The interesting thing is they claimed that they&#x27;re a student, haven&#x27;t installed the app, have no intention to do so, but care a lot about privacy. Essentially they want to show that they&#x27;re merely an underdog bystander standing up against my wrongdoings. I thought this is a very subtle psychological trick, aiming to amplify their attacks.<p>Other attacks are more direct. For example, a person pointed out that since I don&#x27;t have many followers on Twitter, I&#x27;m not a good engineer. They said I didn&#x27;t really contribute anything to my public research, but I just took credit from my coauthors. That I am only cleaning toilet at Google, there&#x27;s nothing proud about that.<p>After I posted a rebuttal to the developers&#x27; rebuttal, a guy [2] dropped this one-line comment:<p>&gt;cái vụ này bắt đầu thấy nhảm rồi. Lập luận của anh Thái cũng không còn chặt chẽ như trước nữa.<p>Which translates to &quot;This is getting nonsense. Thai&#x27;s argument is not as strict as before&quot;.<p>The title of the guy&#x27;s blog [3] is, I kid you not, &quot;There&#x27;s always only one truth: Communist Party of Vietnam.<p>[1] <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Public_opinion_brigades" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Public_opinion_brigades</a><p>[2] <a href="https:&#x2F;&#x2F;www.blogger.com&#x2F;profile&#x2F;17567201928186857755" rel="nofollow">https:&#x2F;&#x2F;www.blogger.com&#x2F;profile&#x2F;17567201928186857755</a><p>[3] <a href="http:&#x2F;&#x2F;phichnuocnong.blogspot.com&#x2F;" rel="nofollow">http:&#x2F;&#x2F;phichnuocnong.blogspot.com&#x2F;</a>
评论 #22991245 未加载
评论 #22994478 未加载
评论 #22992363 未加载