Apple and Google release sample code, UI screenshots, detailed policies for COVID-19 exposure notification apps, including prohibiting location data collection
Apple and Google are providing additional resources for developers working with the first version of their Exposure Notification API …
TechCrunchDarrell Etherington
Context & Ripple Effects
This developer-resources drop lands between two earlier beats in the same arc: the [[a:952996|April FAQ where Apple and Google pledged to disable the APIs once the pandemic is contained]], and the May launch of the Exposure Notification API to the public on iOS and Android. With at least three US states already building apps, the pair is moving from API to productization — sample code, UI screenshots, and written policies that tell health authorities exactly what a compliant app looks like.
The headline constraint is the prohibition on collecting location data, which hardens the privacy posture they staked out earlier and pre-empts the expert qualms raised around the API's debut.
First-order effects
State health departments and their contractors building on the API now have concrete templates and enforceable rules to code against, with location tracking explicitly off the table.
Apple and Google convert their privacy pledges into binding app-store policy, giving them a review lever over every exposure-notification app submitted.
Second-order effects
Any state or vendor that wanted GPS-based contact tracing must redesign around Bluetooth-only proximity data or forgo the built-in OS support entirely.
Third-party infrastructure efforts like the Linux Foundation's tracker-app initiative inherit a fixed rulebook, standardizing what publicly funded COVID-19 apps can do across jurisdictions.
Third-order effects
Two private platform owners are effectively writing the regulatory spec for government health software — a template that likely extends as they later ship the interoperable framework for states and cross-country interoperability updates.
If the pattern holds, OS-level API governance becomes the default mechanism through which privacy limits are imposed on public-sector mobile apps, ahead of any legislation.
The trend: Apple and Google are using OS-level API governance rather than legislation to set de facto privacy standards for public-health software.
There is a very careful discussion to be had around how Apple and Google are imposing policy decisions as opposed to technical decisions with their contact tracing project.
Apple & Google are imposing American values on the world by limiting the usefulness of contact tracing apps. The values aren't privacy, they're distrusting govt & the individual is more important than the health of society (see gun violence, healthcare) https://www.reuters.com/..…
I wish it would have, but this won't impact Aarogya Setu and the Indian govts policy of collecting both Bluetooth and Location data in its app. It's only applicable on apps designed using Apple-Google contact tracking system. That said, it shows Setu collects excessive data. http…
https://www.theregister.co.uk/ ... “It will work if people open the app and leave it open and the phone unlocked. But if you close it and forget to reopen it, or the phone falls asleep, the app will not broadcast its ID ...”
OK, I'm starting to agree with @stewartbaker that Apple & Google are taking the privacy thing too far: https://www.reuters.com/... Keeping location data on the phone for contact tracing for 14 days, along with the bluetooth contact data, is privacy sensitive and reasonable.
Information on how to get the exposure notification entitlement is now available in the docs. TL;DR: only one entitlement per country, only for government entities or developers endorsed by government entities. https://developer.apple.com/ ... (Thanks @Desoukie)
There are very sound engineering reasons for Apple/Google to control how apps can access location and BTLE. But the decision that public health apps cannot see any data about contact matches - even where they are - is not an engineering decision. It's a policy decision.
Apple and Google are doing the right thing by not letting contact-tracing apps have access to phone location. Among the questions we need to ask: — Should two companies have that much power? — Will governments force them to turn on location? — Will use be mandatory? https://twitt…
Just tested: Apple's Exposure Notification ‘Service’ is enabled by default in iOS 13.5 beta — meaning phones will be broadcasting Proximity ID's even without an app installed. Hopefully @Apple will change this to be opt-in in the final iOS 13.5 release? https://developer.apple.co…
“Apple and Google said they will not allow use of GPS data along with the contact tracing systems. The decision will require public health authorities who want to use GPS location data to rely on unstable workarounds to detect encounters using Bluetooth sensors.” https://twitter.…
Apple and Google confirm they will use App Store rules to forbid apps using their Exposure Notification API from using (or even asking for permission to use) GPS/location services too. https://techcrunch.com/...
The UK contact-tracing app relies on self-reporting?! Trolls are just going to bluejack everyone they've been near by self-reporting when they're actually fine. Apple and Google's protection against that is a *good thing* http://news.sky.com/...
Google and Apple have clarified a few more privacy restrictions for the apps that will use their Bluetooth-based Covid-19 exposure alert system. They've also shown some examples of what it could look like: http://wired.com/...... This will not be a fun push notification to get. h…