{"id":237646,"date":"2021-04-28T20:33:27","date_gmt":"2021-04-28T17:33:27","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/an-android-bug-let-some-apps-improperly-access-covid-19-tracing-data-review-geek\/"},"modified":"2021-04-28T20:33:27","modified_gmt":"2021-04-28T17:33:27","slug":"an-android-bug-let-some-apps-improperly-access-covid-19-tracing-data-review-geek","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/an-android-bug-let-some-apps-improperly-access-covid-19-tracing-data-review-geek\/","title":{"rendered":"#An Android Bug Let Some Apps Improperly Access COVID-19 Tracing Data \u2013 Review Geek"},"content":{"rendered":"<p><strong>&#8220;#An Android Bug Let Some <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">App<\/a>s Improperly Access COVID-19 Tracing Data \u2013 Review Geek&#8221;<\/strong><\/p>\n<div id=\"article-content-area\">\n<figure style=\"width: 1920px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-80202 size-full\" src=\"https:\/\/www.reviewgeek.com\/p\/uploads\/2021\/04\/41cf3e74.png?width=1200\" alt=\"Google Android figure standing on laptop keyboard with code in background\" width=\"1920\" height=\"1080\" data-crediturl=\"https:\/\/www.shutterstock.com\/image-photo\/new-york-usa-july-2-2018-1137339098\" data-credittext=\"quietbits\/Shutterstock.com\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><figcaption class=\"wp-caption-text\"><span class=\"imagecredit\"><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.shutterstock.com\/image-photo\/new-york-usa-july-2-2018-1137339098\">quietbits\/Shutterstock.com<\/a><\/span><\/figcaption><\/figure>\n<p><span>A <\/span><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.theverge.com\/2021\/4\/27\/22405425\/android-google-contact-tracing-bug-privacy\"><span>privacy flaw<\/span><\/a><span> in the Android version of Apple and Google\u2019s COVID-19 exposure notification app potentially allowed other preinstalled apps to see sensitive data, including if users had contact with a COVID-positive person. Google is now working on rolling out a fix.<\/span><\/p>\n<p><span>Privacy analysis firm <\/span><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/blog.appcensus.io\/2021\/04\/27\/why-google-should-stop-logging-contact-tracing-data\/\"><span>AppCensus<\/span><\/a><span> first noticed the bug in February and reported it to Google. However, according to <\/span><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/themarkup.org\/privacy\/2021\/04\/27\/google-promised-its-contact-tracing-app-was-completely-private-but-it-wasnt\"><i><span>The Markup<\/span><\/i><\/a><span>, Google failed to address it at the time. The bug goes against multiple promises made by Apple CEO Tim Cook, Google CEO Sundar Pichai, and several public health officials that the data collected from the exposure app would not be shared beyond an individual\u2019s device.<\/span><\/p>\n<p><span>\u201cThe fix is a one-line thing where you remove a line that logs sensitive information to the system log. it doesn\u2019t impact the program, it doesn\u2019t change how it works,\u201d said Joel Reardon, co-founder and forensics lead of AppCensus in the same interview with <\/span><i><span>The Markup<\/span><\/i><span>. \u201cIt\u2019s such an obvious fix, and I was flabbergasted that it wasn\u2019t seen as that.\u201d<\/span><\/p>\n<p><span>The article also shared a quote from Google spokesperson Jos\u00e9 Casta\u00f1eda, who stated \u201cWe were notified of an issue where the Bluetooth identifiers were temporarily accessible to specific system level applications for debugging purposes, and we im<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/social-mediaa\/\" data-internallinksmanager029f6b8e52c=\"1\" title=\"Social Media\" target=\"_blank\" rel=\"noopener\">media<\/a>tely started rolling out a fix to address this.\u201d<\/span><\/p>\n<figure style=\"width: 1600px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-80203 size-full\" src=\"https:\/\/www.reviewgeek.com\/p\/uploads\/2021\/04\/9630e89c.png\" alt=\"Hands holding Android phone and iPhone together displaying their logos, respectively\" width=\"1600\" height=\"900\" data-crediturl=\"https:\/\/www.shutterstock.com\/image-photo\/sydney-australia-20200502-hands-holding-mobile-1722465757\" data-credittext=\"Daria Nipot\/Shutterstock.com\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><figcaption class=\"wp-caption-text\"><span class=\"imagecredit\"><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.shutterstock.com\/image-photo\/sydney-australia-20200502-hands-holding-mobile-1722465757\">Daria Nipot\/Shutterstock.com<\/a><\/span><\/figcaption><\/figure>\n<p><span>In order for the exposure notification system to work, it needs to ping anonymized Bluetooth signals of devices with the system activated. Then, in the event one of the users tests positive for COVID-19, it works with health authorities to send an alert to other users who came into contact with that person with corresponding signals that are logged in the phone\u2019s memory.<\/span><\/p>\n<p><span>The issue is that, on Android phones, contract-tracing data is logged in privileged system memory. While most of the apps and software running on these devices don\u2019t have access to this, apps that are preinstalled by manufactures like Google or LG or Verizon do have special system privileges that allow them to potentially access these data logs, making them vulnerable.\u00a0<\/span><\/p>\n<p><span>AppCensus has found no indications that any preinstalled apps have collected data, however, nor did it find this to be the case with the exposure notification system on iPhones. The company\u2019s Chief <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/technology\/\" data-internallinksmanager029f6b8e52c=\"4\" title=\"Technology\" target=\"_blank\" rel=\"noopener\">Technology<\/a> Officer, Serge Egelmen, emphasized <\/span><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/v0max\/status\/1387016943526244356\"><span>on Twitter<\/span><\/a><span> that the bug is an implementation issue and not the fault of the exposure notification system and that it should damage the public\u2019s trust in public health technologies.\u00a0<\/span><\/p>\n<p><small><span>via <\/span><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.theverge.com\/2021\/4\/27\/22405425\/android-google-contact-tracing-bug-privacy\"><span>The Verge<\/span><\/a><\/small>\n<\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p><script>\nsetTimeout(function(){\n  !function(f,b,e,v,n,t,s)\n  {if(f.fbq)return;n=f.fbq=function(){n.callMethod?\n  n.callMethod.apply(n,arguments):n.queue.push(arguments)};\n  if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version='2.0';\n  n.queue=[];t=b.createElement(e);t.async=!0;\n  t.src=v;s=b.getElementsByTagName(e)[0];\n  s.parentNode.insertBefore(t,s)}(window, document,'script',\n  'https:\/\/connect.facebook.net\/en_US\/fbevents.js');\n  fbq('init', '1137093656460433');\n  fbq('track', 'PageView');\n  },3000);\n<\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more like this article, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/technology\/\" target=\"_blank\" rel=\"noopener\">Technology category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/www.reviewgeek.com\/80201\/an-android-bug-let-some-apps-improperly-access-covid19-tracing-data\/\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#An Android Bug Let Some Apps Improperly Access COVID-19 Tracing Data \u2013 Review Geek&#8221; quietbits\/Shutterstock.com A privacy flaw in the Android version of Apple and Google\u2019s COVID-19 exposure notification app potentially allowed other preinstalled apps to see sensitive data, including if users had contact with a COVID-positive person. Google is now working on rolling out&#8230;<\/p>\n","protected":false},"author":1,"featured_media":237647,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/www.reviewgeek.com\/p\/uploads\/2021\/04\/41cf3e74.png","fifu_image_alt":"","footnotes":""},"categories":[18],"tags":[],"class_list":["post-237646","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/237646","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=237646"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/237646\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/237647"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=237646"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=237646"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=237646"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}