Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It might tip off to people that they are being observed by the police. That would be my guess.


This seems plausible.

I'm not sure how frequently the codes are refreshed, but you could just hide a bluetooth receiver near the police station to get the daily codes for most officers, transmit that to your phone and have an app that tells you if a police officer is nearby.


The key that identifies your phone is changed every 20 minutes.

https://twitter.com/hadleybeeman/status/1309013275745685511?...


Won't it just tell you if a police officer is within 2 meters for 15 minutes?

Except for undercover or plain clothes police officers this doesn't seem like a big deal.


The tracing app itself will only tell you that but you can receive the BLE signals with other bluetooth sniffer apps.


The codes are refreshed "every ten to twenty minutes" according to the Twitter thread linked above


A bit of background. Every app that is intended to be actually used by a people essentially must use the framework included in the OS. Otherwise it would run into various roadblocks like not being able to properly run in the background or not having the required BLE access. So that leaves you with using the cross platform exposure notification frameworks on both iOS and Android. The way those work well documented https://covid19.apple.com/contacttracing. The "Temporary Expose Key" (TEK) changes exactly every 10 minutes. How often the BLE MAC changes depends on the OS, but that's around 10-20 minutes. As you have to change both "fingerprints" at the same time to prevent tracking across individual changes (See also [1]), in practice the sent TEK is changed at the BLE MAC change interval. So that's where to 10-20 minutes come from.

[1] A mostly theoretical flaw (as you need a large network of BLE scanners) on some devices: https://hackaday.com/2020/09/03/covid-tracing-framework-priv...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: