COVIDSafe
   HOME

TheInfoList



OR:

COVIDSafe was a
digital contact tracing Digital contact tracing is a method of contact tracing relying on tracking systems, most often based on mobile devices, to determine contact between an infected patient and a user. It came to public prominence in the form of COVID-19 apps during ...
app released by the
Australian Government The Australian Government, also known as the Commonwealth Government, is the national government of Australia, a federal parliamentary constitutional monarchy. Like other Westminster-style systems of government, the Australian Government i ...
on 26 April 2020 to help combat the ongoing
COVID-19 pandemic The COVID-19 pandemic, also known as the coronavirus pandemic, is an ongoing global pandemic of coronavirus disease 2019 (COVID-19) caused by severe acute respiratory syndrome coronavirus 2 (SARS-CoV-2). The novel virus was first identif ...
. The app was intended to augment traditional
contact tracing In public health, contact tracing is the process of identifying persons who may have been exposed to an infected person ("contacts") and subsequent collection of further data to assess transmission. By tracing the contacts of infected individua ...
by automatically tracking encounters between users and later allowing a state or territory health authority to warn a user they have come within with an infected person for 15 minutes or more. To achieve this, it used the
BlueTrace BlueTrace is an open-source application protocol that facilitates digital contact tracing of users to stem the spread of the COVID-19 pandemic. Initially developed by the Singaporean Government, BlueTrace powers the contact tracing for the TraceT ...
and Herald protocol, originally developed by the
Singaporean Government The Government of Singapore is defined by the Constitution of Singapore to mean the executive branch of the state, which is made up of the president and the Cabinet. Although the president acts in their personal discretion in the exercise o ...
and
VMWare VMware, Inc. is an American cloud computing and virtualization technology company with headquarters in Palo Alto, California. VMware was the first commercially successful company to virtualize the x86 architecture. VMware's desktop software ru ...
respectively, to passively collect an anonymised registry of near contacts. The efficacy of the app was questioned over its lifetime, ultimately identifying just 2 confirmed cases by the time it was decommissioned on 16 August 2022.


History

COVIDSafe first began development in late March, shortly after the
Morrison Government The Morrison government was the federal executive government of Australia, led by Prime Minister Scott Morrison of the Liberal Party of Australia, between 2018 and 2022. The Morrison government commenced on 24 August 2018, when it was sworn ...
showed interest in Singapore's
TraceTogether TraceTogether is a digital system implemented by the Government of Singapore to facilitate contact tracing efforts in response to the COVID-19 pandemic in Singapore. The main goal is quick identification of persons who may have come into close co ...
app. Development of the app was publicly announced on 14 April 2020, with plans to release it for Android and iOS within a fortnight. The app had a budget of over , of which went to
Amazon Web Services Amazon Web Services, Inc. (AWS) is a subsidiary of Amazon.com, Amazon that provides Software as a service, on-demand cloud computing computing platform, platforms and Application programming interface, APIs to individuals, companies, and gover ...
(AWS) for hosting, development, and support. The announcement was immediately met with concerns over the privacy implications of the app and confusion over its distribution. For many, it was unclear if the app would be a feature of the existing
Coronavirus Australia Coronavirus Australia was an app released by the Australian Government designed to allow users to access information about the COVID-19 pandemic in Australia. The app was released by the Department of Health on 29 March 2020, and decommission ...
app or completely separate. Adding to the confusion, many news reports used images of Coronavirus Australia in their articles, and the COVIDSafe website linked to the Coronavirus Australia apps for a short time after release. The app launched on 26 April 2020. However, there were early reports that some users had problems with the sign-up. For example, those who entered their phone number during sign-up received the following message: "Error verifying phone number. Please check your details and try again." Within 24 hours of COVIDSafe's release it had been downloaded by over a million people, and within 48 hours more than two million. By the second week more than four million users had registered. Despite this, state and territory health authorities were not able to access data collected through the app as the health authority portal had not yet been completed. Accompanying the release,
Peter Dutton Peter Craig Dutton (born 18 November 1970) is an Australian politician who has been leader of the opposition and leader of the Liberal Party since May 2022. He has represented the Queensland seat of Dickson in the House of Representatives sinc ...
, then
Minister for Home Affairs An interior minister (sometimes called a minister of internal affairs or minister of home affairs) is a cabinet official position that is responsible for internal affairs, such as public security, civil registration and identification, emergency ...
, announced new legislation that would make it illegal to coerce one into submitting a contact report, even if a person had already registered with the app and tested positive for COVID-19. A
determination Determination is a positive emotional feeling that involves persevering towards a difficult goal in spite of obstacles.Kirby, L.D., Morrow, J., & Yih, J. (2014). The challenge of challenge: Pursuing determination as an emotion. In M. M. Tugade, ...
, titled ''Biosecurity Determination 2020'', was put in place, with the ''Privacy Amendment (Public Health Contact Information) Bill 2020'' being later introduced on 6 May 2020 to codify it. The legislation further governs how data collected by the app will be stored, submitted and processed. In early May 2020, the
Senate A senate is a deliberative assembly, often the upper house or chamber of a bicameral legislature. The name comes from the ancient Roman Senate (Latin: ''Senatus''), so-called as an assembly of the senior (Latin: ''senex'' meaning "the el ...
Select Committee on COVID-19 held a public hearing on the app, focusing particularly on its effectiveness and privacy implications and the
source code In computing, source code, or simply code, is any collection of code, with or without comments, written using a human-readable programming language, usually as plain text. The source code of a program is specially designed to facilitate the wo ...
for the app was released publicly. In mid May 2020, the Australian Chief Medical Officer announced that the app was fully functional. The next day it was reported that the app had reached 5.7 million downloads, approximately 23% of Australia's total population. On 20 May 2020, data was accessed for the first time following an outbreak at Kyabram Health in
Victoria Victoria most commonly refers to: * Victoria (Australia), a state of the Commonwealth of Australia * Victoria, British Columbia, provincial capital of British Columbia, Canada * Victoria (mythology), Roman goddess of Victory * Victoria, Seychelle ...
. By mid June, over a month since the launch of the app, the app had yet to identify any contacts not already discovered through traditional contact tracing techniques, strengthening growing concerns over the efficacy of the app. Adding to this, some estimates put the likelihood of the app registering a random encounter at just ~4%. Concurrently, the
Google Google LLC () is an American multinational technology company focusing on search engine technology, online advertising, cloud computing, computer software, quantum computing, e-commerce, artificial intelligence, and consumer electronics. ...
/
Apple An apple is an edible fruit produced by an apple tree (''Malus domestica''). Apple fruit tree, trees are agriculture, cultivated worldwide and are the most widely grown species in the genus ''Malus''. The tree originated in Central Asia, wh ...
exposure notification framework began rolling out to users, with the
Italian Italian(s) may refer to: * Anything of, from, or related to the people of Italy over the centuries ** Italians, an ethnic group or simply a citizen of the Italian Republic or Italian Kingdom ** Italian language, a Romance language *** Regional Ita ...
Immuni being the first app to make use of it. In late June, following a "second wave" in
Victoria Victoria most commonly refers to: * Victoria (Australia), a state of the Commonwealth of Australia * Victoria, British Columbia, provincial capital of British Columbia, Canada * Victoria (mythology), Roman goddess of Victory * Victoria, Seychelle ...
sparked by family gatherings, COVIDSafe data was accessed by contact tracers over 90 times. The app, again, was unable to identify undetected transmission. At the same time, a COVID-19 positive
protest A protest (also called a demonstration, remonstration or remonstrance) is a public expression of objection, disapproval or dissent towards an idea or action, typically a political one. Protests can be thought of as acts of coopera ...
er who attended the
Melbourne Melbourne ( ; Boonwurrung/Woiwurrung: ''Narrm'' or ''Naarm'') is the capital and most populous city of the Australian state of Victoria, and the second-most populous city in both Australia and Oceania. Its name generally refers to a met ...
Black Lives Matter Black Lives Matter (abbreviated BLM) is a decentralized political and social movement that seeks to highlight racism, discrimination, and racial inequality experienced by black people. Its primary concerns are incidents of police bruta ...
rally on 6 June 2020 was criticised in the media for having not downloaded the app. Despite the identification of at least two further cases in attendance, to date no transmission has been found to originate from the protests. On 20 July 2020, the government was criticised for contracting out part of the app's development and support to a company with ties to the
Liberal Party The Liberal Party is any of many political parties around the world. The meaning of ''liberal'' varies around the world, ranging from liberal conservatism on the right to social liberalism on the left. __TOC__ Active liberal parties This is a li ...
. Mina Zaki, the wife of the
CEO A chief executive officer (CEO), also known as a central executive officer (CEO), chief administrator officer (CAO) or just chief executive (CE), is one of a number of corporate executives charged with the management of an organization especially ...
of Delv Pty Ltd, was a Liberal Party candidate for the federal seat of Canberra in the 2019 election. Delv was engaged after the initial release of the app to assist with development, and was also the primary developer of the
Coronavirus Australia Coronavirus Australia was an app released by the Australian Government designed to allow users to access information about the COVID-19 pandemic in Australia. The app was released by the Department of Health on 29 March 2020, and decommission ...
app. In a 22 July 2020
Sky News Sky News is a British free-to-air television news channel and organisation. Sky News is distributed via an English-language radio news service, and through online channels. It is owned by Sky Group, a division of Comcast. John Ryley is the hea ...
interview,
Minister for Government Services The Minister for Government Services is the minister in the Government of Australia responsible for Services Australia. The current minister since 1 June 2022 is the Hon Bill Shorten MP, who also serves as Minister for the National Disability In ...
Stewart Robert blamed the failure of COVIDSafe on the unwillingness of Apple and Google to modify their existing, globally deployed, Exposure Notification framework (ENF) to work with the app. ENF is an alternative, entirely incompatible, digital contact tracing protocol considered to be more reliable at detecting contact traces than competing protocols. For the app to take advantage of the framework, either the framework or app would need to be almost completely rewritten. On 1 August 2020,
NSW Health The New South Wales Ministry of Health, branded NSW Health, is a ministerial department of the New South Wales Government. NSW Health supports the executive and statutory roles of the Minister for Health, the Minister for Regional Health, an ...
announced the app had helped them trace new contacts. They accessed the app data on a coronavirus case and identified 544 additional people, two of whom tested positive to COVID-19. By late October, the app had identified a total of 17 new cases. By 29 November 2020, the
Digital Transformation Agency The Digital Transformation Agency (DTA) – an executive agency within the Australia’s Government’s Finance portfolio – supports the digital transformation of government services. Since 1 July 2022 it has done this by: * providing strate ...
was reportedly considering incorporating VMWare's
Herald A herald, or a herald of arms, is an officer of arms, ranking between pursuivant and king of arms. The title is commonly applied more broadly to all officers of arms. Heralds were originally messengers sent by monarchs or noblemen to ...
protocol to improve performance and detection success rate. On 19 December 2020, the Digital Transformation Agency announced the app had been updated to incorporate VMWare's
Herald A herald, or a herald of arms, is an officer of arms, ranking between pursuivant and king of arms. The title is commonly applied more broadly to all officers of arms. Heralds were originally messengers sent by monarchs or noblemen to ...
protocol, to improve app performance. The update reportedly helps address situations where communication between devices might fail, such as when the device is locked or the app is running in the background. On 2 February 2021, the Digital Transformation Agency announced a new update enabling the app to display state and territory COVID-19 case statistics. The update reportedly allowed users to change their registration postcode from within the app, which previously required reinstallation. It was announced on 26 February 2021 that the app had been updated to feature state and territory restrictions, as well as improving battery consumption on Android devices. Because of the ongoing technical problems surrounding the COVIDSafe app, the Victorian government developed the Service Victoria QR Code app to augment tracing efforts within the state. Use of the app is mandatory for all Victorian businesses, organisations, clubs and events. Similarly, every other state and territory in Australia has their own QR-code based solution: On 2 December 2021, NSW and Victorian health officials admitted to The Guardian that the data collected by the app had not been used a single time in 2021, despite the extensive outbreaks and lockdowns that year. In response to the poor performance of the app, Federal Labor Party politicians called for the app to be discontinued, while the
Morrison Government The Morrison government was the federal executive government of Australia, led by Prime Minister Scott Morrison of the Liberal Party of Australia, between 2018 and 2022. The Morrison government commenced on 24 August 2018, when it was sworn ...
began engaging with states to find a future use of the app. On 16 August 2022, the incumbent Albanese Government decommissioned the app, shutting down remaining infrastructure and removing it from Google Play and the Apple App Store. The total cost of the app over its lifetime rounded out to $21 million, with $10 million going to development costs alone.


Contact tracing

The app is built on the
BlueTrace BlueTrace is an open-source application protocol that facilitates digital contact tracing of users to stem the spread of the COVID-19 pandemic. Initially developed by the Singaporean Government, BlueTrace powers the contact tracing for the TraceT ...
protocol originally developed by the Singaporean Government. A stated priority of the protocol was the preservation of privacy. In accordance with this, personal information is only collected once at the point of registration and subsequently used purely to contact potentially infected patients. Additionally, users are able to opt out at any time, clearing all personal information. The contact tracing mechanism is executed locally on an individuals's device using
Bluetooth Bluetooth is a short-range wireless technology standard that is used for exchanging data between fixed and mobile devices over short distances and building personal area networks (PANs). In the most widely used mode, transmission power is limi ...
, storing all encounters in a contact history log chronicling contact for the past 21 days. Users in contact logs are identified using anonymous time-shifting "temporary IDs" issued by a central
Department of Health A health department or health ministry is a part of government which focuses on issues related to the general health of the citizenry. Subnational entities, such as states, counties and cities, often also operate a health department of their ow ...
(DoH) server. Consequently, a user's identity and contact patterns cannot be determined by anyone not authorised by the DoH. Furthermore, since temporary IDs change on a regular basis, malicious third parties cannot track users by observing log entries over time. Once a user tests positive for infection, the DoH requests their contact log. If consent is given, the logs are transmitted to a central server where temporary IDs are matched with contact information. Health authorities are not able to access log entries about foreign users, so those entries are sent to the appropriate health authority to be processed domestically. Once a contact has been identified, the DoH contacts the individual. Although the app is commonly described as only logging encounters longer than 15 minutes and closer than , the app actually indiscriminately logs most encounters. It is only once the health authority receives a contact log that it is filtered to encounters within those parameters.


Reporting centralisation

BlueTrace's employment of a centralised reporting architecture has created concerns over its privacy implications. Under a centralised report processing protocol, a user must upload their entire contact log to a health authority administered server, where the health authority is then responsible for matching the log entries to contact details, ascertaining potential contact, and ultimately warning users of potential contact. In contrast, the Exposure Notification framework and other decentralised reporting protocols, while still having a central reporting server, delegate the responsibility of processing logs to clients on the network. Instead of a client uploading their contact history, it uploads a number from which encounter tokens can be derived by individually. Clients then check these tokens against their local contact logs to determine if they have come in contact with an infected patient. Inherent in the fact the protocol never allows the government access to contact logs, this approach has major privacy benefits. However, this method also presents some issues, primarily the lack of human in the loop reporting, leading to a higher occurrence of false positives. Decentralised reporting protocols are also less mature than their centralised counterparts.


Protocol change to Exposure Notification

During the 6 May 2020
Senate A senate is a deliberative assembly, often the upper house or chamber of a bicameral legislature. The name comes from the ancient Roman Senate (Latin: ''Senatus''), so-called as an assembly of the senior (Latin: ''senex'' meaning "the el ...
Select Committee public hearing on COVID-19 and the COVIDSafe app, the
Digital Transformation Agency The Digital Transformation Agency (DTA) – an executive agency within the Australia’s Government’s Finance portfolio – supports the digital transformation of government services. Since 1 July 2022 it has done this by: * providing strate ...
(DTA) announced they were looking into transitioning the protocol from BlueTrace to the Google and Apple developed
Exposure Notification The (Google/Apple) Exposure Notification (GAEN) system, originally known as the Privacy-Preserving Contact Tracing Project, is a framework and protocol specification developed by Apple Inc. and Google to facilitate digital contact tracing during ...
framework A framework is a generic term commonly referring to an essential supporting structure which other things are built on top of. Framework may refer to: Computing * Application framework, used to implement the structure of an application for an op ...
(ENF). The change was proposed to resolve the outstanding issues related to performance of third-party protocols on
iOS iOS (formerly iPhone OS) is a mobile operating system created and developed by Apple Inc. exclusively for its hardware. It is the operating system that powers many of the company's mobile devices, including the iPhone; the term also includes ...
devices. Unlike BlueTrace, the Exposure Notification frameworks runs at the
operating system An operating system (OS) is system software that manages computer hardware, software resources, and provides common services for computer programs. Time-sharing operating systems schedule tasks for efficient use of the system and may also in ...
level with special privileges not available to any third-party frameworks. The adoption of the framework is endorsed by multiple technology experts. Transitioning from BlueTrace to ENF presented several issues, most notably that, as the app cannot run both protocols simultaneously, any protocol change would be a hard cut between versions. This would result in the app no longer functioning for any users who had not yet updated to the ENF version of the app. Additionally, the two protocols are almost completely incompatible, meaning the vast majority - all but the UI - of the COVIDSafe app would have to be redeveloped. Similarly, because of the change from a centralised reporting mechanism to a decentralised one, very little of the existing
server Server may refer to: Computing *Server (computing), a computer program or a device that provides functionality for other programs or devices, called clients Role * Waiting staff, those who work at a restaurant or a bar attending customers and su ...
software would be usable. The role of state and territory health authorities in the process would also change significantly, as they would no longer be responsible for determining and contacting encounters. This change would involve retraining health officials and penning new agreements with states and territories. Up until at least 18 June 2020, the DTA was experimenting with ENF, however in an interview with The Project held on 28 June 2020, Deputy Chief Medical Officer Dr Nick Coatsworth stated COVIDSafe would "absolutely not" transition to ENF. He reasoned the government would never transition to any contact tracing solution without human-in-the-loop reporting, something that no decentralised protocol can support.


Issues


Issues on iOS

Versions 1.0 and 1.1 of COVIDSafe for
iOS iOS (formerly iPhone OS) is a mobile operating system created and developed by Apple Inc. exclusively for its hardware. It is the operating system that powers many of the company's mobile devices, including the iPhone; the term also includes ...
did not scan for other devices when the application was placed in the background, resulting in far fewer recorded contacts than was possible. This was later corrected in version 1.2. Additionally, until the 18 June 2020 update, a bug existed where locked iOS devices were unable to fetch new temporary IDs. Devices collected 24–48 hour pools of temporary IDs in advance, meaning a device could easily exhaust it's pool unless the phone was unlocked specifically when the app was scheduled to replenish the pool. Additionally, all third-party digital contact tracing protocols experience degraded performance on iOS devices, particularly when the device is locked or the app is not in the foreground. This is a characteristic of the operating system, stemming from how iOS manages its battery life and resource priority. The Android app does not experience these issues because Android is more permissive with background services and the app can request the operating system to disable battery optimisation.


Country calling code restrictions

COVIDSafe requires an Australia mobile number to register, meaning foreigners in Australia need a local
SIM card file:SIM-Karte von Telefónica O2 Europe - Standard und Micro.jpg, A typical SIM card (mini-SIM with micro-SIM cutout) file:Sim card.png, A smart card taken from a Global System for Mobile Communications, GSM mobile phone file:Simkarte NFC SecureE ...
. Initially, residents of
Norfolk Island Norfolk Island (, ; Norfuk: ''Norf'k Ailen'') is an external territory of Australia located in the Pacific Ocean between New Zealand and New Caledonia, directly east of Australia's Evans Head and about from Lord Howe Island. Together with ...
, an external territory of Australia, were unable to register with the app as they used a different
country code Country codes are short alphabetic or numeric geographical codes (geocodes) developed to represent countries and dependent areas, for use in data processing and communications. Several different systems have been developed to do this. The term '' ...
to mainland Australia, +672 instead of +61. The Australian government released an update resolving the issue on 18 June 2020.


Privacy concerns

Upon announcement, the app was immediately met with widespread criticism over the potential privacy implications of tracking users. While some criticism was attributed to poor communication, fears were further stoked when
Prime Minister A prime minister, premier or chief of cabinet is the head of the cabinet and the leader of the ministers in the executive branch of government, often in a parliamentary or semi-presidential system. Under those systems, a prime minister is not ...
Scott Morrison Scott John Morrison (; born 13 May 1968) is an Australian politician. He served as the 30th prime minister of Australia and as Leader of the Liberal Party of Australia from 2018 to 2022, and is currently the member of parliament (MP) for t ...
and Deputy
Chief Medical Officer Chief medical officer (CMO) is the title used in many countries for the senior government official designated head of medical services, sometimes at the national level. The post is held by a physician who serves to advise and lead a team of medical ...
Paul Kelly refused to rule out the possibility of making the app compulsory, with Morrison stating the next day it would not be mandatory to download the app. Additionally, several privacy watchdogs raised concerns over the data collected by the app, and the potential for the centralised reporting server to become a target for hackers. To address concerns, the
Attorney General In most common law jurisdictions, the attorney general or attorney-general (sometimes abbreviated AG or Atty.-Gen) is the main legal advisor to the government. The plural is attorneys general. In some jurisdictions, attorneys general also have exec ...
launched an investigation into the app to ensure it had proper privacy controls and was sufficiently secure. The
Minister for Home Affairs An interior minister (sometimes called a minister of internal affairs or minister of home affairs) is a cabinet official position that is responsible for internal affairs, such as public security, civil registration and identification, emergency ...
,
Peter Dutton Peter Craig Dutton (born 18 November 1970) is an Australian politician who has been leader of the opposition and leader of the Liberal Party since May 2022. He has represented the Queensland seat of Dickson in the House of Representatives sinc ...
, also announced special legislation to protect data collected through the app. The app was supposed to be
source available Source-available software is software released through a source code distribution model that includes arrangements where the source can be viewed, and in some cases modified, but without necessarily meeting the criteria to be called open-sourc ...
to allow it to be audited and analysed by the public, however, this was delayed until a review by the
Australian Signals Directorate Australian Signals Directorate (ASD), formerly the Defence Signals Directorate (DSD) is the federal statutory agency in the Australian Government responsible for foreign signals intelligence, support to military operations, cyber warfare, and ...
had been completed. On 8 May 2020, the source code was released. Issue was also taken with the fact the backend of the app runs on the
Amazon Web Services Amazon Web Services, Inc. (AWS) is a subsidiary of Amazon.com, Amazon that provides Software as a service, on-demand cloud computing computing platform, platforms and Application programming interface, APIs to individuals, companies, and gover ...
(AWS) platform, meaning the
US Government The federal government of the United States (U.S. federal government or U.S. government) is the national government of the United States, a federal republic located primarily in North America, composed of 50 states, a city within a feder ...
could potentially seize the data of Australian citizens. Data is currently stored within Australia in the AWS Sydney region data centre. In a public hearing on COVIDSafe, Randall Brugeaud,
CEO A chief executive officer (CEO), also known as a central executive officer (CEO), chief administrator officer (CAO) or just chief executive (CE), is one of a number of corporate executives charged with the management of an organization especially ...
of the
Digital Transformation Agency The Digital Transformation Agency (DTA) – an executive agency within the Australia’s Government’s Finance portfolio – supports the digital transformation of government services. Since 1 July 2022 it has done this by: * providing strate ...
, explained that the decision to use AWS over purely Australian owned cloud providers was done on the basis of familiarity, scalability, and resource availability within AWS. The AWS contract was also drawn from a whole of government arrangement. Following the global rollout of the
Google Google LLC () is an American multinational technology company focusing on search engine technology, online advertising, cloud computing, computer software, quantum computing, e-commerce, artificial intelligence, and consumer electronics. ...
and
Apple An apple is an edible fruit produced by an apple tree (''Malus domestica''). Apple fruit tree, trees are agriculture, cultivated worldwide and are the most widely grown species in the genus ''Malus''. The tree originated in Central Asia, wh ...
developed
Exposure Notification The (Google/Apple) Exposure Notification (GAEN) system, originally known as the Privacy-Preserving Contact Tracing Project, is a framework and protocol specification developed by Apple Inc. and Google to facilitate digital contact tracing during ...
Framework (ENF) in late June 2020, public concerns were raised that the government or the companies were tracking users without their knowledge or consent. These claims are false, as COVIDSafe and ENF are completely incompatible, and ENF is disabled until a compatible app is installed and explicit user consent is given. Even if a third party were to obtain the encounter log of a user, no persons could be identified without also holding the logs of other users the client has encountered. Australia's Inspector-General of Intelligence and Security reported that several of Australia's intelligence and security agencies collected data from COVIDSafe in its first months of operation. The report does not state which specific agencies collected the data and whether or not it was decrypted. In June 2021 the state government of Western Australia "was forced to introduce legislation" when Western Australian police used data collected by the COVID SafeWA app for purposes other than contact tracing. Police stated that their use of this data was lawful, and that they could not stop using this data in criminal investigations while lawful to do so. Police Commissioner Chris Dawson defended this by pointing out that the "terms and conditions stated data could be accessed for a lawful reason" and while he accepts "people don't always read fine print on insurance policies or whatever," their use of the data in these circumstances was lawful.


Attorney General privacy impact assessment

On 25 May 2020, the Attorney General report and subsequent response by the Department of Health was released, the following recommendations were made: * Release the Privacy Impact Assessment and the app source code * Major changes should be reviewed for privacy impact * A legislative framework put in place to protect the user * Certain screens be rearranged to better communicate information * Make clear what a user should do if they are pressured to reveal their contact logs, or are pressured into installing the app * Generalised collection of age * Gather consent from users both at registration, and at submission of contact logs * Create a specific privacy policy for the app * Make it easier to rectify personal information * Raise public awareness about the app and how it works * Development of training and scripts for health officials * Put in place contracts with state and territory health authorities * Allow users to register under a pseudonym * Seek independent review over security of the app * Review the contract with AWS * Ensure ICT contracts are properly documented * Investigate ways to reduce the number of digital handshakes * A special consent process for underage users In the Department of Health's response, they agreed to all suggestions with exception to "rectification of personal information". Rather than building a process to do so, a user could uninstall and reinstall the app to change their personal information. A process to formally correct information was to be introduced later.


Independent analysis

On 29 May 2020, a group of independent security researchers including
Troy Hunt Troy Adam Hunt is an Australian web security consultant known for public education and outreach on security topics. He created Have I Been Pwned?, a data breach search website that allows users to see if their personal information has been com ...
, Kate Carruthers, Matthew Robbins, and Geoffrey Huntley released an informal report raising a number of issues discovered in the
decompiled A decompiler is a computer program that translates an executable file to a high-level source file which can be recompiled successfully. It does therefore the opposite of a typical compiler, which translates a high-level language to a low-level lan ...
app. Their primary concerns were two flaws in the implementation of the protocol that could potentially allow malicious third parties to ascertain static identifiers for individual clients. Importantly, all issues raised in the report were related to incidental leaking of static identifiers during the encounter handshake. To date, no code has been found that intentionally tracks the user beyond the scope of contact tracing, nor code that transmits a user's encounter history to third parties without the explicit consent of the user. Additionally, despite the flaws discovered through their analysis, many prominent security researchers publicly endorse the app. The first issue was located in , the
class Class or The Class may refer to: Common uses not otherwise categorized * Class (biology), a taxonomic rank * Class (knowledge representation), a collection of individuals or objects * Class (philosophy), an analytical concept used differentl ...
responsible for advertising to other BlueTrace clients. The bug occurred with a supposedly random, regularly changing three-byte string included in that was, in fact, static for the entire lifetime of an app
instance Instantiation or instance may refer to: Philosophy * A modern concept similar to ''participation'' in classical Platonism; see the Theory of Forms * The instantiation principle, the idea that in order for a property to exist, it must be had by ...
. This string was included with all handshakes performed by the client. In OpenTrace this issue did not occur, as value changes every 180 seconds. While likely not enough entropy to identify individual clients, especially in a densely populated area, when used in combination with other static identifiers (such as the phone's model) it could have been used by malicious actors to determine the identity of users. This issue was addressed in the 13 May 2020 update. The second issue was located in , the class responsible for managing BLE peripheral mode, where the cached read payload is incorrectly cleared. Although it functioned normally when a handshake succeeded, a remote client who broke the handshake would have received the same TempID for all future handshakes until one succeeded, regardless of time. This meant a malicious actor could always intentionally break the handshake and, for the lifetime of the app instance, the same TempID would always be returned to them. This issue was resolved in OpenTrace, yet was unfixed in COVIDSafe until the 2020-05-13 update. Other issues more inherent to the protocol include the transmission of device model as part of the encounter payload, and issues where static device identifiers could be returned when running in GATT mode. Many of these are unfixable without redesigning the protocol, however they, like the other issues, pose no major privacy or security concerns to users.


Legislation

The ''Biosecurity Determination 2020'', made with the authority of the
Biosecurity Act 2015 The ''Biosecurity Act 2015'' is an Act of the Parliament of Australia which manages biosecurity risks in Australia. It was enacted on 16 June 2015, after the Bill was passed with bipartisan support on 14 May 2015. It covers both agricultural ...
, governs how data collected by the COVIDSafe app is stored, submitted, and processed. Later a separate bill was introduced to codify this determination, the ''Privacy Amendment (Public Health Contact Information) Bill 2020''. The determination and bill makes it illegal for anyone to access COVIDSafe app data without both the consent of the device owner and being an employee or contractor of a state or territory health authority. Collected data may be used only for the purpose of contact tracing or anonymous statistical analysis, and data also cannot be stored on servers residing outside Australia, nor can it be disclosed to persons outside Australia. Additionally, all data must be destroyed once the pandemic has concluded, overriding any other legislation requiring data to be retained for a certain period of time. The bill also ensures no entity may compel someone to install the app. Despite this there have been reports of multiple businesses attempting to require employees to use the app.


See also

*
COVID-19 apps COVID-19 apps include mobile-software applications for digital contact-tracing - i.e. the process of identifying persons ("contacts") who may have been in contact with an infected individual - deployed during the COVID-19 pandemic. Numerous ...
*
Telecommunications (Interception and Access) Amendment (Data Retention) Act 2015 The ''Telecommunications (Interception and Access) Amendment (Data Retention) Act 2015'' (Cth) is an Act of the Parliament of Australia that amends the '' Telecommunications (Interception and Access) Act 1979'' (original Act) and the '' Tele ...
*


References


External links


Android app

iPhone app

GitHub

Senate Select Committee on COVID-19 Public Hearing on COVIDSafe, 2020-05-06YouTube

COVIDSafe App Teardown & Panel Discussion
{{COVID-19 pandemic in Australia Government software E-government in Australia COVID-19 pandemic in Australia Software associated with the COVID-19 pandemic Android (operating system) software IOS software 2020 establishments in Australia Mass surveillance COVID-19 contact tracing apps Morrison Government