Skip to content

Potential privacy issue of new Exposure Notifications Express? #337

@r-r-liu

Description

@r-r-liu

I just installed iOS 13.7 and read about the Exposure Notifications Express (https://developer.apple.com/documentation/exposurenotification/supporting_exposure_notifications_express). This seems to be merely a configurable general purpose app that (a) doesn't need to be installed, but (b) mediates between the user and his PHA's Test verification server and Key server. I see a possible privacy issue here.

Although these servers presumably are under the control of the PHA, on the user side there seems to be nothing but Apple/Google code, and I suppose that Apple and Google are no more likely to submit their code to an audit now than they were when it consisted only of the GAEN api. Yet it might be necessary in the future for a PHA that now decides to the use Exposure Notifications Express to enable certain functionality in the Key server that requires input from the user. That, I suppose, would have to be done in the ENE. That would be the case, for example, if a PHA using ENE decided to support the exchange of exposure notifications with other PHA's. For example, preliminary designs to support, say, users of the Swiss Covid app in Germany, or of the German Covid Warn app in Switzerland, indicate that users might have to specify to their respective backends when they were in the other country, so that each server could pull exposures from the other's backend. Now suppose in this example that one of the countries has no app of its own but is relying on the ENE, and that Apple and Google agree at some point to pass such information through the ENE to the Key server. When that happens, Apple/Google code is effectively handling location information, and absent an audit, nobody knows that it isn't being misused.

I think DP-3T has a vested interest in ensuring that countries, resp. PHA's, that do not wish or cannot afford to develop their own GAEN apps nevertheless enjoy the same level of privacy and security as those that do, and I would encourage you to increase the pressure on Apple/Google to permit a code audit, this independent of any plans that the Swiss FOPH might or might not have to replace SwissCovid by the Exposure Notifications Express.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions