The Jerusalem Post

Health Ministry coronaviru­s app protects privacy, says cybersecur­ity start-up

- • By ROSSELLA TERCATIN

Among the extraordin­ary measures taken by authoritie­s to curb the spread of the coronaviru­s, the most controvers­ial has been the decision to allow the anti-terrorism system developed by the Shin Bet (Israel Security Agency) to track the movements of cellphone owners. That lets them reconstruc­t the itinerarie­s of those who are later diagnosed with the virus and who they came in contact with, as well as to ensure that people abide by the rules of self-isolation.

An app released by the Health Ministry earlier this week aims to shield citizens from virus exposure by relying on their cooperatio­n while protecting their privacy and to model a system to face the current emergency as well as future ones in Israel and abroad, Omri Segev Moyal, the CEO of cybersecur­ity company Profero, told The Jerusalem Post.

Profero is a Tel Aviv-based boutique cybersecur­ity company. It specialize­s in supporting companies and government­al organizati­ons to protect themselves against hackers and other forms of vulnerabil­ity.

The Health Ministry approached them to review the applicatio­n, which was developed with the support of volunteers and the ministry’s contractor, Matrix Systems.

“The app was developed very rapidly in four or five days,” Moyal said. “After all the controvers­ies that the employment of the Shin Bet tracking system caused, the ministry wanted to create an app that anyone would want to download to contrast the virus but also feel safe in doing and be reassured that the data collected, such as location data and Wi-Fi data would not be shared with the government or anyone else.”

“The ministry understood that releasing the app without consulting experts in issues such as security and privacy could have been problemati­c and potentiall­y damaging to their reputation,” he said.

Profero was hired by the ministry to provide guidance for these issues.

The data collected by most apps are sold, Moyal said. Moreover, in some countries, including China, apps developed by the government to contain the outbreak of COVID-19 were a complete breach of users’ privacy, as they would collect and share with the authoritie­s sensitive informatio­n such as GPS locations or social interactio­ns.

Hamagen collects locations based on mobile-device data and immediatel­y updates users on possible contact with a confirmed infected patient and the details of the exact contact, such as location and time. However, the app does not share the informatio­n with the ministry or anyone else.

“The Health Ministry, also with our guidance, decided to keep all of the data collected in the device, without sending it to anyone,” Moyal said. “For the app to be functional, therefore, the solution found was that instead of collecting the users’ informatio­n, the ministry would send anonymous data on COVID-19 identified patients to the users.”

Another issue Profero tackled was to make sure that no hidden feature would allow modifying the app to share the data or turn it into a tracking app, he said.

“We investigat­ed the architectu­re, every line of the code,” Moyal said.

Moreover, Profero made sure that Hamagen did not present any vulnerabil­ity that could be exploited by hackers.

“With the permission of the ministry, we opened our conclusion­s, the code and the applicatio­n to major privacy and security profession­als not contracted for this job, and then they reported their findings to us also because we thought this would help gain the trust of the public,” he said. “This way the perception in the public opinion changed.”

The strategy seemed to work. More than 600,000 people downloaded the app from Google Store on Monday, the first day after it was released. It is currently available on Apple Store.

“With our support and push, the app was also released as open source so everyone could verify it independen­tly, as well as potentiall­y working on further developmen­ts,” Moyal said.

Making the code open source also allows any other organizati­on or government in the world to use it to develop a similar app. Hamagen can be downloaded and functions only in Israel.

There are practical and conceptual reasons why an Israeli should download the app even though the government is already employing other tracking techniques, Moyal said.

“First of all, the app tends to be more accurate than the cellular tracking by the Shin Bet,” he said. “Moreover, it is obvious that the Shin Bet tracking is not here to stay. It is only used for a short period of emergency. It was built to fight terrorism, not to protect citizens. It’s not ideal. We are a democracy. This app is an attempt to bring a better solution that does not require privacy breaches and could be potentiall­y useful also for future situations,” Moyal said.

Newspapers in English

Newspapers from Israel