Track and Trace people OR identifying the spread of Coronavirus? – I think there is f&ck@ry afoot.

Yes, an app to help track the spread of any virus is a good thing.

But ….. Leave the “trace” bit out of the tech solution if the project sponsors are not prepared to deal with commonly understood consequences of bad design decisions that do not reflect the expectations society have on privacy and anonymity.

Just do the right thing. Its easy.

The trigger

This article. www.afr.com/news/politics/national/virus-tracking-app-being-designed-for-privacy-and-security-20200417-p54ktb

talks about storing people’s phone numbers on a database and using software to determine if one persons phone has been near enough to another person to register in the database.

(and another article.. This one is even more ‘worser’ https://www.abc.net.au/news/2020-04-20/government-insists-coronavirus-tracing-app-wont-track-locations/12163756 )

Yes the phone numbers might be encrypted and the uninitiated may believe that “encryption” will keep them safe from prying eyes.

So far, we’ll, sort-of-so-good…..

The problem is social, behavioural and political and to do with both privacy and anonymity protection. Our government agencies have a less-than-perfect track record to do with who has access to the keys to unlock the databases. They have employed senior people in the past that do not believe that citizens of a country have rights to do with privacy nor anonymity. Private data has been exploited and sold without the populations permission or knowledge. The world is full of bright peoples who have the job of joining these databases together to leverage for commercial gain. (It happens each and every day and is not abnormal in the advertising industry for example.)

The naïveté of these sorts of conversations lie in the notion that the app will “only be used for this purpose” and nothing else. History, common sense and logic shows us that this expectation is infantile. This approach to using phone numbers is unacceptable and by design, will decrease the numbers of people who trust enough to use it.

In Australia, we do not live in a society where government is authoritarian and governs via old school, command and control style. The CMO comments about compliance are not well thought out and illustrate just how out of touch some sectors are with how the world actually works.

The problem we are solving is identifying who needs to be tested and measuring how quickly this beast is passed on. That’s it. That’s all.

Ignore all these reporting requirements for this app: Geo spread, case stage tracking (immunised, symptoms, tested positive or negative etc), medico etc are all captured and reported on already. Stop listening to peeps who want it all wrapped up into one reporting tool.

Why does this matter?

If people don’t trust the proposed tracker then they won’t install it or use it or will simply leave their phone at home.

That will make this exercise another waste of time and money. It’s completely foreseeable.

Down the track, this data will be leaked to internal and external entities who will have absolutely brilliant justifications for why they should have access. This is both understandable and foreseeable but not acceptable.

A solution

No GPS nor device nor user nor other identifiable identifier. Not even in the database peeps. You know what I mean 😉

The tracker app has an CV19appID that is randomly generated, is unique and has zero ability to be unpacked to identify the device or person who downloaded the app at any stage by anyone.

The app connects to database with its intended ID and if it’s already taken then it creates another until it’s unique. No tracking on this process.

The app download procedure is unidentifiable. We just want everyone to download it.

The app does the Bluetooth handshake thing and exchanges the apps CV19appID with the other CV19appID that is on a nearby phone. No tracking other than to ensure it’s a unique interaction to avoid over or under counting.

Both phone apps upload into the database to indicate they were in physical proximity for the required time. (Random upload time window of zero to 24 hours?)

If another CV19appID has been in contact within the nominated window then their app says ” go get tested because this device was in close contacted for long enough to warrant you being tested”

The medical place that confirms the outcome of a test ( yes, home tests still need to be verified by sight, potentially at a pharmacy or at Dr reception) has a Bluetooth device for “positive” and “negative” and the test outcome for the CV19appID is uploaded to the cloud.

With some changes and challenges yes but that’s about it!

What it does not do

Users cannot enter their symptoms that the app can use to trigger a suggested action by the user. It is NOT the apps role to then be hijacked by the medicos for them to “streamline” some automated intake or stage management process. That’s the role of a different app that is not connected to the CV19appID identifier nor app. This is key.

Yes, we all know the argument.

If we don’t confirm who they are then how will we “know” for reporting purposes?

The answer: no one cares about your reporting. We care about helping ourselves and our friends and contacts to know if they might need testing. That’s it. Don’t listen to the reporting people’s “requirements”. They are not stakeholders in this opportunity to save lives and money.

We want effectiveness at this stage, not efficiency. Park that psychological driver for the moment and concentrate on the problem, the contagious nature of the beast, not the reporting peeps need for personal gratification nor interdepartmental “requirements” for justification via reports. ( phew it feels good to bring up #vanitymetrics again)

As always, am happy to be challenged and have my mind changed. DM me for that.

Again.

  • App concept is good.
  • Anonymity and Privacy are good.
  • Do both.
  • Why? Because we can.

Related stuff

What should our nation focus on as the COVID-19 pandemic unfolds? #EwansCV19Manifesto

  • Sovereign supply chain risk appetite re-evaluation and accountabilities made public
  • Removal of casual and weekend loading in exchange for all workers holiday, sick leave and other benefits accruing per hour worked
  • Local manufacturing capability safeguarded from lowest-price government and government related purchasing behaviours
  • Government purchasing behaviours for CAPEX items evaluated over lifetime value of asset to help minimise low CAPEX up front with high OPEX tail that becomes someone else’s problem in subsequent periods
  • Removal of any capability for foreign ownership control of any land or significant assets well how is the deal with the Auriel yeah course ridiculous one hour of your crew one hour
    No tax payer funded bailouts.
    Personal guarantees from directors that agree to government short and medium term assistance that is paid back in full
    No assistance to organisations nor employees of same that do not pay full Australian taxes on profits against Australian benchmarks. (Employees need to take responsibility as well)
  • Reduction of the market power of Australian supermarkets
  • Re-nationalisation of previously privatised assets that are not really creating any value
  • Increase tariffs to encourage AU self sufficiency in strategic capability areas
  • Change in investment, taxation and financing policy to decrease the leverage of residential property for investment purposes and return residential property to the status of a ‘home’ so that nearly everyone can afford a roof over their head.
  • Privacy & anonymity freedom will be attempted to be reduced in the name of bio security. Common sense will prevail as the sheeple majoritys’ opinions are ignored by those that understand what is at stake if the CV19 rationalisations are allowed to prevail.

I am a simple man, with a brain, but not fully informed. Different perspectives and beliefs are interesting to me.

I invite debate and to have my mind changed via the usual comms channels. #EwansCV19Manifesto


Some wise words from a good friend, Steve. ”

Our nation has often been scared of change. I recall the failed introduction of a GST. People scared of Medicare propergander. Elections lost over removal of imputation credits.

I would think our self-centred voters would care about their mortgage, their superannuation, their jobs and their holidays.

What should our nation focus on is as different thing to me.

I guess I would have to look back after the great depression to have some idea. But that went for years.

If the restrictions go on for 6 months, I reckon our Aussie will forget within 3 months and again return to their self centred ways.”


When the rules don’t match reality. Does this lead to complacency?

IMHO – Modern day cars don’t achieve sticker promised fuel efficiency promises in real life on real roads anymore.
If they did, there would be less general commentary in the motoring press on the gap between sticker and real life and I would not have experienced this personally in a variety of cars from a multiple manufacturers.
Testing regimes therefore seem to be flawed as they  don’t achieve their core promise which is to simulate real world driving conditions on behalf of the consumer. 
Therefore, the degree to which this VW and BMW thing “exceeds” “regulations” should be kept in perspective given we all “know” that the numbers are nowadays “wrong” as evidenced by our inability to ever achieve the promises of the new car fuel efficiency sticker.

– question: what does it mean for an organisation if they choose to allow themselves to adhere to “rules” that dont match reality?

– question: what does it say about a regulatory authority when it knows thats its core processes and deliverables are broken even though its cause is noble?

– question: what regulatory environment are the market participants actually operating in? The formal or informal?

– CP: follow the cash back to who benefits from this mess
– #vanitymetrics
Lots of articles on this item. Example http://flip.it/VxGg4