Trust In Return for Transparency
Uptake of industry standard practices could boost public trust in contact tracing technologies
The Digital Transformation Agency, responsible for Australia’s contact tracing app, is bucking tech industry trends in their ongoing development of COVIDsafe. But tech industry professionals are concerned that disregarding best practice and industry standards may now pose an obstacle to public trust and lower the effectiveness of the app in the event of a second wave of COVID-19.
According to Prime Minister Scott Morrison, approximately forty percent of the potential user population in Australia had downloaded COVIDsafe at the time of his appearance on the ABC's 7.30 Report on the 21st of July.
At 40%, that's one of the highest rates for an app of that sort in the world
But open source developer Geoffrey Huntley is skeptical about the use of download figures as a measure of success.
The way the DTA respond to independent software developers who discover serious issues in the app could also be improved in the interest of transparency. Open source developers such as Geoffrey Huntley regularly offer “free labour” in service of community security. Geoffrey describes that this relationship between independent researchers and development teams “is best practice, but it’s not being done” when it comes to COVIDsafe.
Responses to the community of COVIDsafe researchers have been very mixed. Richard Nelson describes that after flagging a security issue with the DTA at 11pm on the 5th of May, he received a response early the next morning. He was notified that he had reported a genuine issue, and that a fix would be prioritised.
It was a pretty good turnaround, I was quite impressed with the way they handled that one in particular
But Geoffrey Huntley had a very different experience after reporting a serious breach of the application’s privacy policy. The DTA took 8 days to make contact with Geoffrey, disregarded his follow-up emails, and ignored offers to speak over the phone.
The following software update to the application failed to address the serious breach discovered by Geoffrey. He described the update as akin to “slapping a new coat of paint on the app” and ignoring more serious issues affecting users. The breach to the privacy policy was present for 18 days before partial fixes were added in a software update on the 14th of May.
The prioritisation of development issues is also cause for concern for Richard Nelson. He describes that any team not developing under the modern principles of agile software development “are effectively living in the dark ages”. Agile software development involves responding to fundamental issues over cosmetic ones as they arise.
I would suggest security and privacy should be the top goals for this for this project. Even if you support other languages, you won't have user trust until you fix your privacy issues.
Richard Nelson, Software Developer
The Digital Transformation Agency's dealings with journalists and the general public also speak to the lack of transparency surrounding the app's development.
Geoffrey Huntley flagged that DTA failed to reply to user reviews on both the iOS App Store and Google Play store. He noted that this left leaving many individuals in a state of confusion after since-resolved development oversights left users unable to register for a variety of reasons, including differing mobile number area codes and regional areas being unable to receive confirmation texts over Wi-Fi networks.
Transparency would also have improved the DTA’s response to a critical security vulnerability discovered in the COVIDsafe app in May by Dr Alwen Tiu, Associate Professor at ANU and Jim Mussared, an open-source software developer.
The details of the security threat were placed under a 45-day embargo in May after being. The embargoed report was published online by Dr Tiu and Jim Mussared on the 19th June., but the DTA have yet to acknowledge the severity or existence of the vulnerability, labelled CVE-2020-12856.
But Dr Alwen Tiu describes that this issue was patched by the DTA on the 27th of May without any public announcement. He adds that the joint effort between himself and the DTA to fix the issue was made confidential after the Australian Signals Directorate stepped in to facilitate discussion between the two parties.
Dr Tiu also revealed that he had uncovered a second, equally severe bug in June, which had been reported along with a suggested fix. However, no roadmap to a patch had been revealed to him, nor had a publication date been discussed by the DTA.
The general public will go a long way to trust everything if there's actual data, because data is truth.
We shouldn't focus on whether the number is high or low, or drag anyone over the coals about usage numbers... This is a tool for public health.
