Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Aussie contact-tracing app sent no data and is in breach of privacy policy (theregister.co.uk)
6 points by ghuntley on May 7, 2020 | hide | past | favorite | 3 comments


Geoff here. See https://twitter.com/GeoffreyHuntley/status/12581744339796254... for more information. We are putting together our findings for the Australian senate as a group.

See https://covidsafe.watch/

We need webdevs to send PRs and help out. Jump in discord. ️


Correct me if I am reading it wrong, but doesn't the Android source code for COVIDSafe collect and transmit the device ID (Settings.Secure.ANDROID_ID) as part of the registration info when you register? COVIDSafe supports Android 6.0+, but it wasn't until Android 8.0 that Android made this field unique to each combination of app-signing key, user, and device (rather than simply an unanonymized device ID). Device ID isn't mentioned in their privacy policy, so it would be a breach of their privacy policy, right? It would enable them to track your device, in addition to knowing your phone number, name, postcode, age range etc. You can change your phone number, but you can't change your device ID unless perhaps by doing a factory reset of the phone or buying a new phone that uses Android 8.0+.


What kind of help are you looking for?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: