The security lapses were discovered in May by @fredrecht, a software engineer in Seoul, who was required to use the quarantine app when he returned from travel abroad. He discovered the app had poor encryption and assigned users easily guessable I.D. codes.
By June, Korea had required more than 162,000 people to use its quarantine app.
@fredrecht reported the security problems to the gov't.
Then he contacted @choesanghum, @zhonggg and me.
@Aaron_Krolik tested the app and confirmed the security lapses.
South Korean officials told @choesanghun that they were in such a hurry to release the quarantine app that they prioritized speedy deployment over user safety.
Also, they said they hadn't expected that tens of thousands of foreigners would be required to use the app.
We held the story for more than a month to give the Korean gov't time to address the security lapses.
New versions of the apps were released in the Apple and Google Play stores last week.
The major security lapses with South Korea's quarantine app come after @botherder @amnesty found serious problems with Qatar's virus surveillance app and an analysis of 17 gov't-sponsored virus-tracing apps by @Guardsquare found that the majority could be easily hacked:
An alternate approach for government virus-tracing apps from Apple and Google also has privacy issues.
It uses Bluetooth signals --not location tracking-- to detect smartphones that come near one another. But, In to use the apps, Android users must first turn on location.
But European gov'ts have not told Android users of the virus-tracing apps that, once they turn on location, Google may use Wi-Fi, mobile networks and Bluetooth beacons to determine their precise whereabouts through a setting called location accuracy.
Informed consent?
The potential for Google to collect location data on people who use virus-tracing apps may violate the privacy promises made by governments like the UK (cc: @EinsteinsAttic )
Angela Merkel has urged Germans to use Germany's new virus app, saying it does not collect location data
You can follow @natashanyt.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled:

By continuing to use the site, you are consenting to the use of cookies as explained in our Cookie Policy to improve your experience.