SwissCovid: a critical analysis of risk assessment by Swiss authorities

06/18/2020
by   Paul-Olivier Dehaye, et al.
0

Ahead of the rollout of the SwissCovid contact tracing app, an official public security test was performed. During this audit, Prof. Serge Vaudenay and Dr. Martin Vuagnoux described a large set of problems with the app, including a new variation of a known false-positive attack, leveraging a cryptographic weakness in the Google and Apple Exposure Notification framework to tamper with the emitted Bluetooth beacons. Separately, the first author described a re-identification attack leveraging rogue apps or SDKs. The response from the Swiss cybersecurity agency and the Swiss public health authority was to claim these various attacks were unlikely as they required physical proximity of the attacker with the target (although it was admitted the attacker could be further than two meters). The physical presence of the attacker in Switzerland was deemed significant as it would imply such attackers would fall under the Swiss Criminal Code. We show through one example that a much larger variety of adversaries must be considered in the scenarios originally described and that these attacks can be done by adversaries without any physical presence in Switzerland. This goes directly against official findings of Swiss public authorities evaluating the risks associated with SwissCovid. To move the discussion further along, we briefly discuss the growth of the attack surface and harms with COVID-19 and SwissCovid prevalence in the population. While the focus of this article is on Switzerland, we emphasize the core technical findings and cybersecurity concerns are of relevance to many contact tracing efforts.

READ FULL TEXT
research
09/13/2020

Proximity Tracing in an Ecosystem of Surveillance Capitalism

Proximity tracing apps have been proposed as an aide in dealing with the...
research
06/18/2020

A Survey of COVID-19 Contact Tracing Apps

The recent outbreak of COVID-19 has taken the world by surprise, forcing...
research
08/11/2020

Report prepared by the Montreal AI Ethics Institute In Response to Mila's Proposal for a Contact Tracing App

Contact tracing has grown in popularity as a promising solution to the C...
research
12/06/2020

On the Privacy and Integrity Risks of Contact-Tracing Applications

Smartphone-based contact-tracing applications are at the epicenter of th...
research
04/17/2021

Risk score learning for COVID-19 contact tracing apps

Digital contact tracing apps for COVID-19, such as the one developed by ...
research
04/30/2021

DeFiRanger: Detecting Price Manipulation Attacks on DeFi Applications

The rapid growth of Decentralized Finance (DeFi) boosts the Ethereum eco...
research
09/22/2021

Gotta catch 'em all: a Multistage Framework for honeypot fingerprinting

Honeypots are decoy systems that lure attackers by presenting them with ...

Please sign up or login with your details

Forgot password? Click here to reset