Countries that raced to deploy coronavirus-tracking software are now fielding complaints over extensive data mining and poor security practices
As countries race to deploy coronavirus-tracking software, researchers are reporting privacy and security risks that could affect millions … Tweets: @nytimesbusiness , @antoniocasilli , and @puiwingtam Tweets: @nytimesbusiness : As countries race to deploy coronavirus-tracking software, researchers are reporting privacy and security risks that could affect millions of people and undermine trust in public health efforts. https://www.nytimes.com/... Casilli / @antoniocasilli : “In fact, the vast majority of virus-tracing apps used by governments lack adequate security and are easy for hackers to attack (...). It's a cautionary tale for governments aggregating such an enormous amount of data.” https://www.nytimes.com/... Pui-Wing Tam / @puiwingtam : Norway put an interim ban on its virus-tracing app. Major security flaws were found in Qatar's app. And India's app was found to leak users' locations. @natashanyt https://www.nytimes.com/...
Context & Ripple Effects
Contact-tracing software went from experiment to government infrastructure in weeks: after China and South Korea first used smartphones to track COVID-19 patients in March, the field had grown to dozens of apps by late April (dozens of tracking apps in use or development), with India alone claiming 75M+ downloads of its app (India's 75M+ download figure) while privacy advocates flagged its potential as a state-surveillance tool beyond the pandemic.
The July reckoning was predictable from the corpus: researchers had warned about security since the apps appeared, China's tracking effort had already been described as messy and poorly coordinated across agencies, and the US state-by-state rollout was flagged for creating security and interoperability problems. Now named failures are surfacing — major security flaws in Qatar's app, an interim ban on Norway's app, and a leak of users' location data from India's app.
First-order effects
- Norway has suspended its own tracing app pending review, while Qatar and India face pressure to fix disclosed vulnerabilities — flaws in apps installed on millions of phones, including the location leak in India's 75M+-download tool.
- Researchers like Casilli are documenting that most government virus-tracing apps lack adequate security, turning individual app bugs into a systemic indictment of rushed deployments.
Second-order effects
- Trust erosion directly threatens the public-health goal: if users uninstall or refuse to install insecure apps, governments lose the adoption these tools depend on, forcing officials to choose between transparency and uptake.
- Privacy advocates' surveillance-beyond-pandemic concern gets concrete evidence to cite, strengthening calls in countries like India — where the app's scale makes it uniquely potent as a precedent — to impose retention limits and independent audits on government health software.
Third-order effects
- If the pattern holds, emergency-deployed health surveillance becomes the test case for whether democratic governments accept permanent digital monitoring infrastructure: either post-pandemic sunset clauses and security-audit requirements become standard procurement conditions, or crisis-speed deployment normalizes surveillance systems built without them.
- The Norway ban sets a template other governments can copy when their own apps fail audit — making independent security review a gatekeeper function in public-health tech rather than an afterthought.
The trend: Pandemic-era contact tracing is entering its accountability phase, where the speed-versus-scrutiny tradeoff of spring deployments collides with security audits, bans, and demands that government surveillance software meet the same standards as commercial products.