In a recent security update, most Android and iOS phones received a new opt-in setting related to the COVID-19 Exposure Notification system. What is this? Is your phone being tracked with a new tracking app? Letโs take a deeper look at what is going on.
Weโve seen a few social media posts over the last week or so claiming that Android and iPhones have been getting a COVID-19 tracking app installed without getting permission from the user first. People are worried that their privacy is at risk. Here is an example of one of the posts that have been making rounds across Facebook:
**VERY IMPORTANT ALERT!***
A COVID-19 sensor has been secretly installed into every phone.
Apparently, when everyone was having โphone disruptionโ over the weekend, they were adding COVID-19 Tracker [SIC] to our phones!
If you have an Android phone, go under settings, then look for google settings and you will find it installed there.
If you are using an iPhone, go under settings, privacy, then health. It is there but not yet functional.
The App can notify you if youโve been near someone who has been reported having COVID-19.
There is a little bit of misinformation here. First of all, there really isnโt a way to sneak a โsensorโ onto a device through a software update unless there is already some hardware in place that does the sensing for the tracking app. This immediately tells us that something about this is at least a little bogus, because from a technical standpoint, the sensationalist post misses the mark.
Hereโs what really happened.
Google/Apple Didnโt Sneak a COVID-19 Tracking App On Your Phone – They Pushed a Security Setting
Google and Apple have been working together to build a framework that app developers can use for apps that notify users if they may have been exposed to COVID-19. They didnโt sneak a COVID-19 app onto your phone without your consent.
The two companies added a setting to enable the use of Google and Appleโs COVID-19 Exposure Notification system. This system is the groundwork that official COVID-19 notification apps can use. State and local governments are responsible for developing the apps, but they can use Google and Appleโs secure platform in order to get them to work.
If you follow the steps in the article and on Android, go to Settings and then Google Settings, youโll see that the option to opt-in is disabled. The same with iPhone users; by going under Settings, then Privacy, then Health, youโll have an option to opt in.
Even if you opt in, you still need to install one of the official apps, most of which arenโt even released yet. Again, this is just the groundwork.
This Isnโt a COVID-19 Tracking App
Just to be perfectly clear, unless you manually installed something, your Android or iPhone isnโt just going to start tracking you and your friends and family to see if you have COVID-19. If you go into your settings as mentioned in the above Facebook post, youโll see that you either need to install or finish setting up a participating app before the notifications can even be turned on.
Apple and Google even confirm this in a joint statement saying โWhat weโve built is not an app – rather public agencies will incorporate the API into their own apps that people install.โ
API stands for Application Programming Interface. Basically, Google and Apple have developed a standardized system to make it easier for states and local governments to build an effective app to notify users if they may have been exposed to COVID-19, but Google and Apple arenโt building the apps or pushing them out to users. .
Itโs worth mentioning that the system wonโt work effectively if users donโt adopt it – if half of all users decide they wonโt use the COVID-19 notification system, it might not be reliable enough to do much good. We donโt want to sound pessimistic, maybe as states and local governments work to deploy their applications, people will come around.
How Does the COVID-19 Exposure Notification Work?
The system is still in its infancy, and itโs really up to state and local governments to deploy the official apps themselves. Google and Apple just laid out a secure system that these apps can piggyback on.
It works like this; when you opt in and use one of these apps, a random ID is generated and exchanged between your phone and other nearby phones (that also opted in) within Bluetooth range. Thatโs about 30 feet, generally. These random, anonymous IDs are stored on your phone. Basically, your phone keeps track of other phones it has been near without collecting or sharing any personally identifiable information.
If someone is diagnosed with COVID-19 and manually shares that information with one of the official contact tracing apps, all of the random IDs your phone has collected over the past 14 days are uploaded (with your permission) and the users of those IDs are notified that they may have been exposed.
Most importantly, the system doesnโt track your location, or share other usersโ identities within the app, or even with Google or Apple. According to Google, the apps are not allowed to use your phoneโs location or track your location in the background.
In short, the technology is very secure and anonymous, which is good, because it has to fall under the strict rules that govern healthcare data.
Many Still Ask: How Do You Uninstall the Apple/Google COVID-19 Exposure Notification?
Since this API isnโt actually an app, you canโt uninstall it. Itโs built into Android and iOSโs operating systems and pushed through recent security updates. Itโs simply a setting that lets you decide if you want to opt in or not.
If you search around the Internet and social media, youโll run across instructions that might walk you through rolling back your phone or other risky procedures, but that only puts your phone at risk for other threats. There is nothing to uninstall, and rolling back your phone and preventing future security updates from ever getting installed is a very bad idea.
All you need to do is not opt in, if you donโt want to participate. If you are worried about it, both Apple and Google state that by simply not installing a COVID-19 Exposure Notification app, or uninstalling one if you did install one, is all it takes to not participate.
WE CANโT STRESS THIS ENOUGH: DO NOT FOLLOW ANY INSTRUCTIONS ONLINE THAT WALK YOU THROUGH ROLLING BACK YOUR PHONE AND OPTING OUT OF SECURITY UPDATES.
Opting out of future security updates only puts your privacy and your data at even more risk.
Of course, the choice to opt in or out of the COVID-19 Exposure Notification system is yours to make, but Google and Apple appear to be doing all the right things to ensure that the system is safe and secure, without violating anyoneโs privacy. If you have any questions or concerns about your privacy, or the security of your data, donโt hesitate to reach out to us at WheelHouse IT.