2021/06 COVID-19 Apps in Test Pdf, 3 MB
Total Page:16
File Type:pdf, Size:1020Kb
REPORT COVID APPS SECURITY BENCHMARK Corona Warning App In its first year, the German Corona app experienced a turbulent history, but also received many functional improvements. The Corona warning app has been avail- effectiveness of the contact tracing and an able in Germany since June 2020. After improved accuracy of the risk assessment. long discussions during preparations, the Still, the criticism of its limited usefulness consortium of Deutsche Telekom and SAP, led to the app continually adding more fea- with the support of the Robert Koch Insti- tures: Since late 2020 (version 1.10), it tute (RKI), had the app up and running in offers a contact diary in which, for example, a fairly short time. In the first five days, it meetings among family and friends can reached almost 11 million users, but then be registered. Since March 2021 (version the enthusiasm stagnated. Today, the app 1.13), voluntary data donations for scientific counts around 28 million users. With a research have been possible, and in April penetration of around 34 percent of the (version 2.0), event registration was added. population, Germany leads the field in our This allows organizers to generate a QR comparison of countries. However, even code for their events in the app and publish this figure is still a long way from the 60 to it, for example, on a poster. Participants can 70 percent that experts demand for maxi- then scan it via the app. With the latter mum effectiveness of contact warnings. function, the providers also responded to For distance detection via Bluetooth LE, alternative but now controversially dis- the app uses the “Exposure Notification cussed advances such as the „Luca“ app. Framework“ built by Google and Apple into Since May (version 2.1), the results of rapid High warning threshold: Most users their mobile operating systems; since the tests can be noted in the app. For some see a „low risk“. Vice versa, this means that warnings issued by the end of 2020, it has been using its more rapid test sites, identification is now also app should be taken seriously. precisely working version 2.0. In principle, possible via a test profile stored in the app. the app runs on iPhone 5s and iOS version And by the end of June, the digital vaccina- ANTI VIRUS APPS REPORT 12.5 or higher, on Android version 6 or higher tion certificate currently under development About a year after the launch of the Corona warning app in Germany, now is a good time – although Android smartphones require a is planned to be integrated. However, critics to review these apps both in Germany and abroad. Our valued and trusted partner for app special supplementary update. Since the point out that such additional functions are REPORT end of 2020, the app can also be used on also available via other apps. security tests, umlaut, has paid particular attention to possible weaknesses in the apps. Huawei devices despite the lack of “Google In connect 9/2020, we already tested the Services“ thanks to a group of free deve- security of the then current versions 1.0.4 lopers. Downloading the app is possible via (Android) and 1.0.2 (iOS) together with t the beginning, hopes a closer look at exactly these perform well in this respect, the alternative app store, „F Droid.“ umlaut and were able to certify top results were still high: digital tech- aspects. Germany is ahead – in terms of per- The trigger level of the warnings can be for the Corona warning app: 976 points nology and clever software formance and also regarding app adjusted on the server side. After messages (“outstanding“) for the iOS version, 932 were supposed to play a German app gets a lot right distribution. But read for yourself. about a possibly increased risk often left points (“very good“) for the Android variant. A users perplexed, the programmers raised In the comparison at hand, we restrict central role in containing the As is inevitable with the topic of Hannes Rügheimer this threshold. Now, however, there is once ourselves to the version for the more wide- Covid 19 pandemic. But it soon Covid-19, the discussion about the again criticism that the app warns inconsis- spread and less “bulkheaded“ Android. became clear that the reach of Corona warning apps is very emo- tently. Even though the warning function The version 2.0.4 examined by umlaut Corona warning apps is barely tional. It is often said in Germany makes an important contribution to asses- could increase its result to 940 points – its sufficient for digital alerts to reach that our strong focus on data protec- sing the risk of infection, its analyses are still developers obviously considered some of their full potential – in Germany tion hinders the effi ciency of the only reliable to a limited extent due to the the suggestions for improvements identified and beyond. warning app and that other coun- insufficient penetration. In view of the fre- in our first test. Thus, the app now achieves quent exten sions of Corona restrictions, the full score in the data security category. Still, even with limited population tries have found better compromi- „We can certify the Corona warning this led to increasing criticism of the app – The security of data traffic remained un- penetration, the warning apps can ses on this issue. In order to enable the ardously negotiated decentralized sto- changed and still offers minor possibilities apps to offer a good or partly even help protect their users and break a factual examination of this thesis, rage principle is accused of favoring data for optimization. The testers identified chains of infection. Nevertheless, umlaut examined not only the cur- very good level of security and protection too one-sidedly. It should be noted, somewhat greater potential for improve- data protection. App providers from the goal is that these apps should be rent status of the German warning however, that while the theoretical alterna- ment in integrity protection (the “Imperso- many countries achieve convincing much more effective. app but also its equivalents in seve- tive of centralized data storage would better nation attacks“ category). Here the solu- results. Still, German app users allow ana lyses of the infection incidences tions from Australia and South Africa rank Even when leaving fundamental ral other countries. The surprising can rely on the best security by the RKI and other government agencies, slightly better. The source code security skeptics aside, many potential users result: although the Covid apps Event Manager: Since April 2021, the rating in our comparison.“ it would hardly have contributed to a wider of the open source project is again at the still seem to distrust the security and from Australia, the UK and the penetration of the app. Yet this alone would top of the test field, but still offers minor app has included registration functions for physical meetings – supporting both be a leverage that could enable greater starting points for optimization. data protection of the warning apps. USA also do a very good job in orga nizers and participants. Hakan Ekmen, For connect and umlaut, this terms of safety, and those from CEO Telecommunication at umlaut Verdict: very good (940 Points) Photo: blvdone/shutterstock.com Photo: pro vided all the more reason to take South Africa and Canada still 82 7/2021 connect.de 7/2021 83 REPORT COVID APPS SECURITY BENCHMARK NHS Covid 19 App Covid Alert NY After an app with centralized data storage first appeared in May 2020, Because a U.S.-wide app was hardly feasible, New York developed its the NHS switched to a privacy-friendly version following strong criticism. own solution. But acceptance remains low despite very good security. Initially, the British National Health Service test can also be booked directly via the app; As it is difficult to balance all 50 U.S. This is because distance detection and (NHS) focused on an app with its own con- the user then decides whether the result states, the state of New York developed notificationa are based on the “Exposure tact tracing technology and centralized data should be uploaded anonymously. If a its own Corona app. The bordering states Notification Framework“ from Apple and storage. But after massive criticism, it later quarantine is imposed, the app counts of New Jersey, Delaware and Pennsylvania Google. The functionalities beyond that switched to the Apple/Google Exposure down the remaining days. Users can also were included to accommodate commuters are moderate. Even positive test results Notification Framework and its decentra- check in at stores or events where the NHS between those states. NearForm Inc. was cannot be uploaded directly; this is the lized storage approach. However, the has put up a poster with a corresponding contracted to develop the application; the responsibility of a health authority re sulting delay meant that the current app QR code. State University of New York (SUNY), employee. could not be launched until September The now privacy-friendly version, which in Columbia University, Cornell Tech and the In any case, security concerns should 2020. On the very first day, it recorded the UK is also known as the “Phase II Covid Massachusetts Institute of Technology (MIT) not deter potential users from installing 6 million downloads. Today, the app has App“, receives an overall very good security were involved as advisers. the app, because the assessment of reached around 22 million users and thus rating from umlaut. In terms of personal data Released in October 2020, the app had “Covid Alert New York“ by the security ex- a similar penetration of the population as protection, it ranks in the midfield of our 500,000 downloads after about a month perts of umlaut also resulted a very good in Germany.