Analysis: COVID-19 Contact-Tracing Privacy Issues episode artwork

EPISODE · Apr 24, 2020

Analysis: COVID-19 Contact-Tracing Privacy Issues

from Info Risk Today Podcast · host InfoRiskToday.com

The latest edition of the ISMG Security Report analyzes the privacy issues raised by COVID-19 contact-tracing apps. Also featured: An update on efforts to fight fraud tied to economic stimulus payments; John Kindervag on the origins of "zero trust."

Episode metadata supplied by the publisher feed · Published Apr 24, 2020

Embed this episode

NOW PLAYING

Analysis: COVID-19 Contact-Tracing Privacy Issues

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

Coronavirus, Contacts of Tracing in Privacy, Frost is focusing on federal stimulus payments and what Ronald Reagan has to do with Zero Trust. He's stories and more, and this week's ISMG Security Report. Hello, I'm Nick Honda. There's a number of words and phrases that have become a part of our common vernacular in the last few months.

Obviously, there's Coronavirus and COVID-19, there's also social distancing and flat in the curve, and then there's another that we're beginning to hear a great deal, which is contact tracing. It's not difficult to translate what that means. It's literally tracing the contact or contacts that an infected individual may have had in recent weeks. It sounds simple, but it's actually very hard to do.

Where did I go? Who did I converse with? What did I touch? Human memory is really not up to the job of tracking our contacts with that degree of granularity, and there are technologies that may present a far better record, such as our smartphones.

However, having our whereabouts tracked opens a fairly heavy can of worms-related privacy. With more on the story, it's ISMG's executive editor, David Richard A. and Europe, Matthew Schwartz. Can contact tracing apps help us keep COVID-19 infections to a minimum?

As the pandemic continues, many nations have introduced or announced plans to introduce smartphone-based contact tracing apps. Such programs may have a public health upside, but more than 200 scientists and researchers this week warns in an open letter that such apps come with risks. Namely, they could facilitate unprecedented surveillance with society at large unless they get rolled out with security and privacy safeguards. Everybody accepts the extraordinary times called for extraordinary measures, but that has to be done in a measured way, and you have to have this public debate about the risk.

That cybersecurity expert, Alan Woodward, he's a visiting professor at the University of Surrey, and he's one of hundreds of signatories to be open letter. Contact tracing apps are meant to augment the laborious manual process of tracking individuals who have tested positive for COVID-19, and then attempting to notify everyone with whom they may have come into contact after infection via telephone. Researchers have said that due to COVID-19 symptoms, sometimes not coming to light for days or weeks, manual contact tracing won't be good enough. Instead, they're looking to technology to help.

One model for how this would work involves users running an app on their smartphone that will send a unique, anonymous ID to any other app within a certain proximity, such as about six feet, for a specified period of time. If a user later tests positive for COVID-19, they can toggle an alert in their app, which will share their unique ID via the cloud and alert all other apps that record having common contact with that ID. But there are numerous debates over the best way to do this. The big, I mean, it really is a big point at the moment, is centralized versus decentralized.

So, for example, should I be doing that risk modelling by capturing all the data on some central server somewhere, or should I be, have some kind of anonymous exchange of tokens with people and analysts who are done on the phone? The risk being, and this is what led to the letter, the risk being that if you try and capture all that data, whilst we all understand extraordinary times call for extraordinary measures, it could actually be misused. It could be used for what's called social graphing. So, you start to track people's movements for all sorts of other purposes.

So, bear in mind that the road to hell is often paid for good intentions. We just want to put a few markers down, one of which was these decentralized approaches are preferred. It has to put privacy as a high factor in this. But also, we've set up .3 of our letter was, if it really is necessary to collect some of this data and processes centrally, then it has to abide by the data protection guidelines already out there, which is you collect only the minimum you need, and you justify it to the public.

And there's some sort of sunset clause. So, eventually it will evaporate, and it can't be misused for other things in the future. These are not academic concerns. Researchers at the University of Oxford estimate that 60% of a country's population will need to use these apps for them to be effective.

But only 80% of the population, at least in the United Kingdom, have smartphones sufficiently advanced to run these apps. In other words, governments must get immediate buy-in from a vast majority of the population when they launch these apps. Arguably, they'll only get one chance to do so, mess up the rollout, and what could be a saving grace instead becomes a liability. This is precisely what the scientists are warning in their open letter, when they emphasize that contact tracing app projects must prioritize openness, transparency, privacy by design, allowing users to opt in, and taking as decentralized an approach as possible.

This is not a bunch of squivelide looms who are sort of all anti-government and saying, we don't believe this is the right thing to do because you're all going to spy on us. We're saying, that is a possibility. So, we just need, and we know how we can build these things, but at the same time, we're all willing to be convinced that there may be good, clinical reasons why you may need something done centrally, but justify that, show us that. For Information Security Media Group, I'm Matthew Schwartz.

The US Treasury Department is anticipating fraud as the IRS works through the largest cash distribution to American residents in history. It's part of a trillion dollar pandemic relief program. It's also an unprecedented opportunity for cyber criminals. Two services the IRS has quickly stood up for people to submit their direct deposit banking details are accessible online.

One of the services is for non-filers or for people below the income threshold required for filing a tax return. That means the IRS does not have their bank account details. Another online service, Get My Payment, is designed for people to submit their direct deposit details. The IRS is also mailing paper checks.

To authenticate taxpayers, both services rely on the usual personal data, names, nailing addresses, birth dates, and social security numbers. That has become ever-riskier to rely upon in an age of unending data breaches, where much of that data has been floating around online on the internet for years. Alex Holden is founder and chief information security officer for Wisconsin-based hold security, which is a cybersecurity consultancy. He says that a scan of Russian language cyber criminal forums and private chats suggests that fraudsters are moving quickly.

They're hoping to capitalize on gaps in fraud controls. Alex Holden. They are basically understanding that the systems are an IRS, and other ways is very much new and not 100% fraud for proof. They're just forging ahead and trying these things.

In a chat, one group appeared to have successfully submitted bank account data for an unsuspecting taxpayer entitled to the stimulus. Other chats indicated fraudsters were also seeking compromised computers running Microsoft's remote desktop protocol. That's in order to access the IRS's website using US IP addresses, so as to not raise suspicions. The Treasury Department has sought to warn people about the potential for fraud, says it won't ask people for personal information by email, text message, or social media.

The US Department of Justice has also set up the Virginia Coronavirus Task Force to investigate financial scams around the payments. There are some hurdles for fraudsters to overcome when trying to steal someone else's payment. For example, if the IRS already has bank account details on file, someone can't just use Get My Payment to change their details. Also, that online service asks for a person's adjusted gross income from previous tax years, or may ask for refund or debt amounts from either those years.

While a fraudster may not know that information, it may just be a matter of tricking a victim into divulging that information through phishing or social engineering. There's been a record rise in domains centered around the pandemic and the economic relief programs, as well as thousands of new dodgy domain names registered. The speed at which the payments are being distributed may mean catching fraud only in hindsight. The IRS has said it will send letters within a couple of weeks to recipients confirming payments that have already gone out.

I spoke with Michael Brett Hood, who's a former FBI supervisory special agent and an adjunct professor of corporate governance and ethics at the University of Virginia. He says it's not uncommon for the IRS to push out money, then worry about fraud after the fact. That makes it more inviting for cyber criminals. But he says Americans are also in tough financial circumstances right now and need help.

Holden agrees. He says the IRS doesn't want to make the mistake of excluding anyone. Alex Holden again. I don't know what IRS can be doing more securely, perhaps putting more to factorification, having some kind of more complexity, like a phone number or anything like that, but implementing this in a short time, not complicating and not excluding certain individuals and stuff.

For Information Security Media Group, I'm Jeremy Kirk. With a recent transition to a remote workforce for a great number of companies, implementation of zero trust framework has very much come of age. So much so, in fact, that ISMG held its first ever virtual cybersecurity summit on the subject of zero trust this week. One of the notable speakers was the godfather of zero trust, John Kindavag, field CTO at Palo Alto Networks.

That's his current cycle, but 10 years ago, as a forest analyst, he coined the phrase zero trust for a research report, inspired rather surprisingly by Ronald Reagan. It's the story in John's own words. So I joined Forrester Research in 2008 after a lot of time in the cyber security reseller community as an engineer. So I'd been a network engineer, security engineer, pen tester, security architect, those technical jobs.

And because of my technical background, I was asked to do research, primary research on why cyber security wasn't working and what we could do about it. And through that research, talking to lots and lots of different people, the thing that kind of came back to me was the idea of this trust model that we had built up inside of networks. The idea that the evil internet was the untrusted side of the network and the internal network was all trusted. And from installing firewalls over a number of years, I had struggled with this trust model developing policy, so I was familiar with it.

But you know, oddly enough, there was a moment in New York City when I was speaking to the CISO of a very, very large company. And I asked him, what's your cyber security strategy? And he said to me, oh, of course, trust would verify. And I said, why is that?

And he said, because Ronald Reagan said we should do that. And that led me to actually going back and seeing what Ronald Reagan actually said. And he didn't say, trust would verify, he was quoting an old Russian proverb in a speech in 1987, or 88 maybe, with Mikhail Gorbachev. And he said, Mr.

Gorbachev, and I'm wildly paraphrasing here, we're excited about this treaty, but we're going to buy by that old Russian proverb. And I'm going to butcher the Russian pronunciation. But he said, we're going to buy by that old Russian proverb, over and I, no prover and I, which of course means trust would verify. And then everybody left.

So Ronald Reagan was making a joke, right? And no one in cyber security or no one in the western hemisphere got the joke. And that was the moment when I did the research, when I researched what Ronald Reagan actually said, I'm so thankful to that CISO in New York City for pointing me in that direction. That's it for this week's Ice and Security Report.

Thing music is why you think audio? I'm Nick Collins, catch you next time.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on April 24, 2020.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!