Jump to content

Recommended Posts

Posted

I don't believe that same venue results in self isolation, for example I scanned into a castle yesterday, massive open area (I know I didn't need to). That's different to a small pub. I believe you get a warning but you are not told to isolate unless the proximity tags are there.

 

My question is, if the a person who used paper track and trace at a venue then gets a positive test, how are the people there notified? Track and Trace surely have to be able to tag that venue as at risk. But Track and Trace have no way to tell anyone who used the App to isolate because they wouldn't know who they were.

 

It makes a bit of a farce of the track and trace really, as no one really knows who should be warned to self isolate whether on paper (as they were there at the same time) where you wouldn't know how close everyone was they were to each other anyway. Or does the paper method assume everyone is infected but the App version assumes only proximity matters?

 

What we have established is getting a working method is nigh on impossible!

Posted
The only bit that I can see that's being missed is that the venue had no way to prove that they've collected the data from everyone who visited.

Exactly why I'd be surprised if businesses aren't still required to gather contact details themselves. I can fully understand why owners might think they don't have to for people who've scanned their code.

 

 

Also, if the proximity party of the app hadn't picked up that you were close to the person who treated positive, how much risk are you actually at? I know I don't need a test unless I have symptoms, but is checking in to a venue at some point during the same day as someone who tested positive enough of a reason for me to self isolate?

Yeah, I'd be interested if anyone knows what the threshold is for matching contacts based purely on having venue scans in common. My main reason for not using the app is that a notification to isolate would be especially unwelcome, so I'd want to feel confident that all of my diligence thus far with mask wearing, social distancing and contact minimisation is going to be undone by a massively trigger-happy app.

Posted
My question is, if the a person who used paper track and trace at a venue then gets a positive test, how are the people there notified? Track and Trace surely have to be able to tag that venue as at risk. But Track and Trace have no way to tell anyone who used the App to isolate because they wouldn't know who they were.

 

Yes they do, they mark the location as infected, and then when your phone downloads the list of infected bluetooth keys and qr codes, it sees if they match to your own internal list

Posted (edited)

This could equally go in the Annoying Things thread, but thought it might be useful for someone here:

 

I got this notification a couple of hours ago:

 

Screenshot_20201005-131331_Opera~2.jpg

 

Turns out it's a system check by Google.

 

https://news.sky.com/story/coronavirus-some-users-of-nhs-tracing-app-incorrectly-given-covid-19-exposure-alerts-12086225

 

It'd be useful if the notification said something along those lines.

 

Apparently if it's a genuine notification it should take you into the app and give useful instructions. This one just disappears when you click on it.

Edited by jmak
  • Thanks 1
Posted
I think that's API/OS rather than the specific app. It's basically saying that a 'contact' has been detected by the system. It's up to the app to determine whether or not that warrants an actual 'stay at home' notice to the user.
Posted

Sorry, but I am not installing that app on my phone.

 

With Dido Harding in charge, having overseen the Talk Talk fiasco, and now with the news that using Excel as the data container means that overflow was the cause of losing over 15,000 contacts, I have zero confidence in it. Who would not be using SQL as the back end for such an app? What a bunch of absolute rank amateurs.

 

If they sack her, I may recant. If I get turned away from anywhere insisting that I use it, I'll go elsewhere.

Posted

It's open source, so you can see if it's terrible or not.

 

The notifications are from Google saying there's a match, but the NHS app only counts if if you were close to someone for 15 mins, or medium distance for 30

 

https://faq.covid19.nhs.uk/article/KA-01252/en-us

 

On android, go to settings>google>exposure notification, you can see what the app is up to

 

'In Exposure Checks , you can see a list of timestamps that are recorded every time your phone receives a list of anonymous ‘keys’.

The figures for number of keys , or provided key count , indicate keys from app users who have newly tested positive for coronavirus (COVID-19). The number of matches or matched key count indicates how many of those app user keys you have been in close contact with'

  • Thanks 1
Posted
Can I ask what you are worried about though? The track and trace app is different than the testing interface. Or is it just a general protest about her having the job?
Posted
Can I ask what you are worried about though? The track and trace app is different than the testing interface. Or is it just a general protest about her having the job?

 

I'm concerned about the general tracking information gathered and the app's potential security vulnerabilities.

Posted

They can't complain about people being too far right.

 

In the past 24 hours I've downloaded

 

1281+1659+1404+1100+177+108+237+432+859+1078+1532+1534=11401 keys

 

A user running the app constantly should create, in 2 weeks, 24 * 14 * 60/17.5 = 1152 keys, however let's assume that people have had the app running for 7 days, so 576 keys per person, that's 20 people reporting positive using the app

 

Let's say 10 million people are running it. And say 8000 new cases per day. So 0.01% of people per day get positive result, so there should be 1200 people per day reporting positive results, hmm.

 

- - - Updated - - -

 

I'm concerned about the general tracking information gathered and the app's potential security vulnerabilities.

 

What information and what kind of security vulnerabilities?

Posted

From an article in Wired that seems to give a fairly comprehensive explanation:

 

https://www.wired.co.uk/article/nhs-covid-19-tracking-app-contact-tracing

 

Who built it and what happens to my data?

No, not Dominic Cummings. The app has been developed by the NHS and NHSX, the innovation arm of the health service, under the direction of the DHSC. There have been a number of other groups involved in the development of the app.

 

The NHS has published a list of all the organisations involved in the app: Accenture, the Alan Turing Institute, NHS Digital, NHSx, Oxford University, VMware Pivotal Lab and Zuhlke Engineering. The UK's National Cybersecurity Centre (NCSC) has also provided technical advice to those working on the app.

 

As fact-checking organisation Full Fact has pointed out, Serco is not involved in the app. The outsourcing firm has been involved in other parts of the test and trace programme but not in the creation of the app.[/Quote]

 

So while Test and Trace is run by Dido Harding, the app was nothing to do with her. One of the reasons I decided to use the app is that I have more faith in that notifying me than the manual process which she is associated with.

 

I don't think there's a suggestion that the back end of the app is running on Excel - it looks like that was designed by someone with some technical nouse. The error was on the process of collecting and publishing statistics - still a big fail, but separate.

Posted
From an article in Wired that seems to give a fairly comprehensive explanation:

 

https://www.wired.co.uk/article/nhs-covid-19-tracking-app-contact-tracing

 

 

 

So while Test and Trace is run by Dido Harding, the app was nothing to do with her. One of the reasons I decided to use the app is that I have more faith in that notifying me than the manual process which she is associated with.

 

I don't think there's a suggestion that the back end of the app is running on Excel - it looks like that was designed by someone with some technical nouse. The error was on the process of collecting and publishing statistics - still a big fail, but separate.

 

Yup article in the Guardian ( I think) suggested that the problem was that the data was sent from the central gathering system on a CSV - which has no limits

 

but was then imported into Excel - and the newest cases were on the end

hence if there were more than about 1 million - or 65,000 on older versions - then the bottom of the csv was just truncated

and no-one noticed

Posted (edited)
Just utter incompetence. Harding is accountable as she is so clueless she wouldn't even know to ask what back end systems and processes they were using when designing the system. Edited by MartinT
Posted
The Excel spreadsheets have got nothing to do with the NHS app. I'm not sure what they use as a backend but since it's open source it wouldn't be too difficult to figure out.
Posted
The Excel spreadsheets have got nothing to do with the NHS app. I'm not sure what they use as a backend but since it's open source it wouldn't be too difficult to figure out.

 

Yeah - sound like the basic system is not to blame in this instance

 

The system overall - which include the communication and transfers of files (Whut - why are we transferring files like this - is it still the 1970s???) - that is still to blame

Posted

What are you telling us so? For the main system that is using some dubious import method and might not be great to have a breach or for the App to have a breach.

 

Given that the App doesn't actually collect your personal data, I don't really get what the breach will be. Someone will be able to see where my phone went and who it has seen over the past how many days, using Google Maps probably does worse then that already!

 

If you mean the actual Test and Trace system, then if you have had a test then you would be included, so you couldn't have told anyone so. Unless you actual mean you wouldn't get a test because you don't trust the system to keep your data safe, that is ultimately your choice. I kind of think unless someone is a selfish idiot, you could easily isolate yourself and not get a test especially if you live by yourself and not get tested. Just remember to take a trip to your local tourist attraction to test your eyesight.

Posted

Yeah, the app is essentially private. My reason for not using it at the moment is that I can't afford for it to be too liberal with its stay at home notices (I've no way to gauge how 'sensitive' the whole ecosystem is on that front). I've not used it but am I correct in thinking that all it asks from you is the first part of your postcode?

 

There's probably some academic risk of tracking via BT beacons or something, and some experts were arguing on that front that the personal keys ought to change more regularly. As for general leak of personal data, well, as @mavhc keeps saying, there isn't any personal data being collected directly through app use. If you're concerned about BT-based tracking/attacks at all, you should perhaps not go about in public with BT on anyway, app or no app.

Posted
Just wait for their first major breach. I'll just say 'told you so'.

 

Good for you. Could I ask what other apps you have on your phone? I mean just having a phone is a tracking device, so a breach at your mobile provider would compromise you. Considering all the good work NHSx has actually put in after the failure earlier in the year, reassurances, and mitigations this just seems like a stubborn stance because you don't like the head of a different department.

 

Even if there was a breach what are you expecting someone to find out? That 98762348634928459823 bumped into 09863498690869. It won't even tell them where those IDs met, just that they were close for 15 minutes.

 

The civil service is actually pretty good at network security, all the data breaches since 1961 have been memory sticks, stolen devices or mislaid information, not hacks.

 

But feel free to stick with the tin foil hat.

Posted

Look, the point I'm making is that someone was put in charge of this fiasco and has proven once again to be incompetent. Why would I put an app on my phone that was developed in such a way, with a possibly dubious back-end and dodgy data manipulation processes tied to it?

 

I don't care whether others are using it or not. I care that a contract was given by the government, without tender, to an organisation that has not developed anything like a 'world class' tracing app. I'm careful with the apps I use and, sure, one or two of them may be vulnerable. If I know about them, I will stop using them too.

 

There's no tin foil hat here, you're the ones who appear to be staunchly defending it.

  • Thanks 1
Posted
I don't care whether others are using it or not. I care that a contract was given by the government, without tender, to an organisation that has not developed anything like a 'world class' tracing app. I'm careful with the apps I use and, sure, one or two of them may be vulnerable. If I know about them, I will stop using them too.

 

i thought it had been established.. nhsx isnt serco... its open source you can check what theyre collecting its all anonymous and relies upon the end users outing themselves once the app says to do so

Posted
Look, the point I'm making is that someone was put in charge of this fiasco and has proven once again to be incompetent. Why would I put an app on my phone that was developed in such a way, with a possibly dubious back-end and dodgy data manipulation processes tied to it?

 

I don't care whether others are using it or not. I care that a contract was given by the government, without tender, to an organisation that has not developed anything like a 'world class' tracing app. I'm careful with the apps I use and, sure, one or two of them may be vulnerable. If I know about them, I will stop using them too.

 

There's no tin foil hat here, you're the ones who appear to be staunchly defending it.

 

I'm not defending the app, I held out installing it until I had a chance to review and look at the facts. I'm pointing out the flaws in your argument to not have it. No personal information is held, the person you have issue with is not involved in the app, the dubious back-end is a completely different system, the dodgy data manipulation is a different system.

 

Just to be clear. Test and Trace, who Dido Harding is in charge of and who 'lost' results and who have been using XLS sheets and who had the fiasco is NOTHING to do with NHSx or the App. You are conflating two very different departments, systems and entities. That is where the issue is. People are trying to point this out to you and you are digitally stamping your foot and digging in. You do you, but do it ofr the right reasons, not because you haven't got the correct facts or are misinformed.

Posted
Just wait for their first major breach. I'll just say 'told you so'.

 

Problem is, they really should be doing a better job with IT in general. This is all about a wider scale problem that exists where no one really cares about IT - "just work". And when it fails, you have that magical reactive state pop up.

 

I don't mind mistakes or issues, they were expected to get a system up and running from scratch. You need the equipment for the workers - coders, engineers and technicians and people supporting them and being run by someone qualified and experienced. Plan of attack on what they all need before the app is even started. Not to mention employing those staff which can take 2 weeks IF they get decent salaries on offer right away - I bet they held the salaries back which meant another 2 weeks if they didn't employ everyone they needed. I wonder what kind of a contract they got offered? 6 months? I wouldn't waste my time even if it offered a lot more salary.

 

That's 4 weeks before you've noted down exactly what this app needs to do.... I've heard it a few times 10 years ago "we need an app!"... sure.. what do you want to do.. "I don't know"..... So, you need backend servers that will hold the data securely (SQL and not a god damn XLS sheet).. it needs to be able to read data from different areas of our country (with some of them using OLD! systems...).. it needs to be live data or updated daily? automatic updating? Some one needs to be importing/linking/connecting that data.. not to mention a good network/broadband for that data.. where does it store it? do they consider using things like O365/Google accounts to link up and email addresses?

 

I bet you had IT people screaming at what they needed... and some IT manager (you know the type.... a bit like that head of ICT that did 6 months of IT support = they are fully qualified to do your job)... just ignoring those screams...

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...