Works on implementing Rapid Antigen Tests into CWA have begun: A RAT portal (for testing staff?), the connected RAT server backend have been published on GH, and app coding (at least for Android, didn't look up iOS) has started.
Unfortunately there is no documentation at all about this new feature yet.
When do you plan to publish such a documentation for assessing technical and security implications, similar to the Event Registration (=presence tracing) documentation?
For now I have only questions with regard to the data embedded into the generated QR code.
From a short code review, I assume following workflow with associated tech specs (which for sure can be far away from the actually planned implementation):
Questions:
If it is indeed intended that the QR code in its current implementation could be used as an entry pass, social engeneering attacks might be possible. A fake gate keeper could scan the QRs en masse with an arbitrary scanning app, extract names and birthdates, find people via telephone books, and use the personal data for better social engeneering attacks like Enkeltrick and alike.
If there is no way to skip or to encrypt the personal data embedded in the QR code for the planned implementation, people must be warned, that the QR code contains personal data and must not be presented publicly or to unauthorized persons (which is not trivial, if blinds, analphabetics or people with language barriers are supposed to be included).
Is there a plan that the RAT QR code can be used as an entry pass to venues, by presenting it to gate keepers?
I think something like this is indeed planned, see https://github.com/corona-warn-app/cwa-app-ios/pull/2422, which implemented the text:
"Auf Wunsch k枚nnen Sie 眉ber die App Ihren pers枚nlichen Infektionsstatus nachweisen (z.B. negativer Schnelltest). Bitte beachten Sie, dass Sie grunds盲tzlich nicht zum Nachweis Ihres Infektionsstatus per App verpflichtet sind. Sie k枚nnen Ihren Infektionsstatus im Rahmen der rechtlichen Bestimmungen an Ihrem Aufenthaltsort auch auf andere Weise nachweisen."
Also, there is the PR https://github.com/corona-warn-app/cwa-app-ios/pull/2437 which introduced a counter which counts how long the test result is already available. Also, it includes this text:
"Sie k枚nnen den hier angezeigten Befund auch als Nachweis f眉r das Vorliegen eines negativen Schnelltest-Ergebnisses verwenden. Informieren Sie sich hierzu bitte auch 眉ber die Kriterien f眉r die Anerkennung von Test-Nachweisen in Ihrem Bundesland. [...]"
Related Issue:
Thanks, @Ein-Tim , you're like a walking library 馃榿
@dsarkar
Hi Dipankar, I hope you had a nice start into the week!
Do you plan to refer this issue to the people in charge? I think would be good not to loose too much time, as RAT implementation for release 2.1 already started.
This is also related and additionally illustrates my questions/doubts/concerns: https://github.com/corona-warn-app/cwa-wishlist/issues/463
Thank you, and have a nice day!
To add one thing here:
Please clarify with Apple & Google if there is a problem with the non-anonymity of the RAT integration.
It is planned that the following personal data is needed: first name, last name, date of birth (see also OP).
@heinezen
Hi Christoph, as @dsarkar seems to be off-charge at the moment - could you provide a short feedback if this issue is already under evaluation/consideration in the associated departments?
Sorry for my impatience, but I think the here discussed points have a non-negliable importance for the further implementation of RAT and I don't want CWA to run into any kind of trouble here..
Thanks a lot, V.
Most helpful comment
To add one thing here:
Please clarify with Apple & Google if there is a problem with the non-anonymity of the RAT integration.
It is planned that the following personal data is needed: first name, last name, date of birth (see also OP).