{"id":4928,"date":"2020-08-29T02:08:13","date_gmt":"2020-08-29T00:08:13","guid":{"rendered":"http:\/\/plus.maciejpiasecki.info\/index.php\/2020\/08\/29\/contact-tracing-api-gaen-labeled-an-election-threat\/"},"modified":"2020-08-29T22:08:21","modified_gmt":"2020-08-29T20:08:21","slug":"contact-tracing-api-gaen-labeled-an-election-threat","status":"publish","type":"post","link":"https:\/\/plus.maciejpiasecki.info\/index.php\/2020\/08\/29\/contact-tracing-api-gaen-labeled-an-election-threat\/","title":{"rendered":"Contact-Tracing API GAEN Labeled An Election Threat"},"content":{"rendered":"<p>GAEN, an API Google and Apple co-developed to curb the spread of COVID-19, has been running like clockwork since May. As a matter of fact, it seems to be working too well.<br \/>\nWhich is one way to reflect on the cybersecurity scrutiny it&#8217;s been been attracting as of late. In fact, things already escalated to the point that GAEN is considered a legitimate threat to democratic processes. That label is equally applicable to both the U.S. and most other parts of the world.<br \/>\nWhich is hardly surprising seeing how the API has so far been used for launching dozens of contact-tracing apps.<br \/>\nYet none of that explains how GAEN \u2013 short for Google-Apple Exposure Notification \u2013 supposedly threatens democratic elections.<br \/>\nThat particular issue was best framed by three New York-based scholars specializing in physics and cryptography. In an in-depth scientific analysis published this week, the said trio explained how GAEN-powered notifications could easily be abused, i.e. faked.<br \/>\nSince the API shares no personally identifiable information, it lives and dies by the procedurally generated and randomly exchanged Bluetooth keys it uses for identifying confirmed cases in one&#8217;s vicinity. Yeah, about that\u2026<br \/>\nGAEN deemed a threat because of notifications<\/p>\n<p>It turns out that obtaining a legitimate Temporary Exposure Key (TEK) through illegitimate means is far from impossible, the analysis explains. An attacker could consequently dispatch immeasurable volume of false exposure detection alerts. Contents aside, a potential hacker&#8217;s ability to time this false-flag operation is even more concerning. Not to mention completely unavoidable: you can always stop your GAEN-powered contact-tracing app from sharing your anonymous data.<br \/>\nNaturally, vice versa also applies, giving a potential attacker full control over the timing of the false notification pings. Based on that train of thought it&#8217;s easy to imagine a setup aimed at scaring unsuspecting voters away from polling places.<br \/>\nIt&#8217;s nowhere near being an active election threat<br \/>\nWhich isn&#8217;t to say large-scale voter-suppression is high on the list of risks associated with GAEN. In spite of its highly demonstrable nature, no one&#8217;s losing sleep over attempts to solve this attack vector. Because the likelihood of it leading to an actual malicious attempt at subverting the November 3rd elections are pretty slim.<br \/>\nJust like you wouldn&#8217;t eat soup with a fork, you wouldn&#8217;t attempt meaningful voter suppression through GAEN. &#8222;Meaningful&#8221; being &#8222;making a difference in the end.&#8221; If we&#8217;re simply talking doing enough to invite felony charges, than yes, GAEN alone would do. That about sums up the early peer review efforts concerning this analysis.<br \/>\nIronically, the easiest way to mitigate this theoretical election risk would be doing away with the API&#8217;s anonimity. Because if any third party was privy to the aforementioned Bluetooth key exchanges, it&#8217;d be able to verify the legitimacy of any such communications. Of course, a shift to a blockchain structure would do the same while preserving user anonimity, though it&#8217;s far from the easiest thing to code. As expected, Google and Apple prioritized speed of deployment above everything else while developing GAEN.<br \/>\nAgain, none of this precludes continued usage of GAEN and similar APIs. Because there&#8217;s still no end in sight to any vaccine development efforts. Which places religious contact tracing near the top of anyone&#8217;s list of best pandemic practices. Besides social distancing, itself, of course.<br \/>\nThe post Contact-Tracing API GAEN Labeled An Election Threat appeared first on Android Headlines.&#013;<br \/>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/plus.maciejpiasecki.info\/wp-content\/uploads\/2020\/08\/Google-Apple-GAEN-Illustration-YouTube-ScreengrabsMockup.jpg\" width=\"1600\" height=\"900\">&#013;<br \/>\nSource: ndroidheadlines.com&#013;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>GAEN, an API Google and Apple co-developed to curb the spread of COVID-19, has been running like clockwork since May. [&hellip;]<\/p>\n","protected":false},"author":14,"featured_media":4929,"comment_status":"false","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-4928","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bez-kategorii"],"_links":{"self":[{"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/posts\/4928","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/comments?post=4928"}],"version-history":[{"count":1,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/posts\/4928\/revisions"}],"predecessor-version":[{"id":4930,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/posts\/4928\/revisions\/4930"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/media\/4929"}],"wp:attachment":[{"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/media?parent=4928"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/categories?post=4928"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/tags?post=4928"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}