Sunday, August 30, 2020

Some musings on the legal foundations of the State of Energency declaration in VIC

 

On 24 August 2020, the Premier of VIC, Daniel Andrews, suggested to extend its state of emergency by 12 months. Predictably, the pushback came hard and fast, with comparisons to a dictator.

My personal feel is that the proposal is one of Too much executive power, too little legislative oversight.

That being said, Daniel Andrews has a point: only VIC has a time limit in how long the state of emergency declared under the Public Health and Wellbeing Act 2008 (Vic). Specifically, s198(7)(c) of the Public Health and Wellbeing Act 2008 (Vic).

While in the other states, notwitstanding that there is a time limit on how long a public health emergency can last, there is no limit on the number of times it can be renewed.

(At this point I think it is pretinent to note that this is different to the State of Disaster, which is declared under the Emergency Management Act 1986 (VIC). The 2 states are declared under different Acts; however they work with each other. It is also pretinent that there is no limit on the number of times a State of Disaster can be renewed)

For example, in QLD, a (public health) emergency can be declared for 90 days maximum, but there is no limit on the number of times it can be extended.

As of 26 Aug 2020, it has been extended 4 times since the declaration on 29 January 2020:

Original notice in the Gazette on 31 Jan 2020:

Extended to 12 Feb 2020 by Public Health (Extension of Declared Public Health Emergency—Coronavirus (2019-nCoV)) Regulation 2020

 

Extended to 19 Feb 2020 by Public Health (Further Extension of Declared Public Health Emergency—Coronavirus (2019-nCov)) Regulation 2020:

 
 

Extended to 19 May 2020 by Public Health (Further Extension of Declared Public Health Emergency—Coronavirus (2019-nCoV)) Regulation (No. 2):

 

Extended to 17 Aug 2020 by Public Health (Further Extension of Declared Public Health Emergency—COVID-19) Regulation (No. 3) 2020

 

Extended to 2 October 2020 by Public Health (Further Extension of Declared Public Health Emergency—COVID-19) Regulation (No. 4) 2020:

 

All the other states have similar legislation form: that is to say, there is no time limit on how long a State of Emergency can be declared.
 
Yet no political swinging on the fact that the other states are dictatoral by having unlimited times to extend a existing declaration of emergency.

I suppose VIC tried to do the right thing from a human rights perspective, however these laws were not designed for a pandemic like what the world is facing with COVID19.

My personal view is that this proposal is still Too much executive power, too little legislative oversight, but one can see the dilemma the VIC government finds itself.

Even the suggestion to require the return of parliament periodically (say, every three or six months) to justify extending the timeframe of its powers is still a higher standard than all the other Australian states.

Coming from Sarawak. a place where the Emergency Ordinance 1966 [P.U.(A)339A/1966] suspended some of Sarawak's Constitutional Rights to deal with a coup against Stephen Kalong Ningkan, and was rubber stamped renewed until it was repealed (ironically, by Najib) in 2011. So I'm no fan of giving governments too much power.

Personally the VIC government could just let the existing state of energency lapse, and declare a new one, to reset the clock. I'd bet there will be legal challenges to it that may have a leg to stand on.
 
My take is that there are no good options on the table for any government in VIC; damned if you do (extend the length of time a state of energency can be declared and be called a dictator), damned if you don't (let the existing declaration lapse and have no legal powers to deal with a pandemic)

Having a knee jerk reaction of opposition to any government extending its powers it warranted, but I think it is fair to don't lose sight of nuance.

Sunday, May 31, 2020

A initial overview of the Sarawak QMUNITY contact tracing application

https://www.thestar.com.my/news/nation/2020/05/29/sarawak-launches-two-contact-tracing-apps-to-stem-covid-19-spread

Contact tracing apps, contact tracing apps everywhere.

So the Sarawak State Government has decided to promote QMUNITY, a contact tracing app created by MBKS.Essentially, it is a "where I've been" recording solution. Call it an app, put a QR code, and people think its "new".

So, what permissions does ask for in Android?

 

There are so many things wrong with this list of application permissions. How did MBKS ever think this was even appropraite for an app, let alone a contact tracing app?

1) Why does a QMUNITY require access to the calendar of the phone? It's task is only to record who visited where at when. To see the details of the calendar, and to be able to modify it, is unnecessary overreach.

2) There is no reason for ANY contact tracing application to readthe contacts of the phone. Whatsapp is bad enough. How does reading the contacts of the user assist in contact tracing?

3) Why does QMUNITY need access to the phone functionality? Nothing in the application functionality asks for cellular voice capabilities.

4) Why does QMUNITY require access to phone storage outside its own container? Reading Photos/Media/Files and storage: how is QMUNITY being able to read the Photos/Media/Files and storage of the user able to assist in contact tracing?

5)  How is QMUNITY needing access to the phone microphone able to assist in contact tracing?

6)  How is knowing the "read phone status and identity" going to assist in contact tracing?

7) "manage document storage"? "change your audio settings"? "draw over other apps"? "control vibration"? "prevent device from sleeping"? "modify system settings"? "read Google service configuration"?

Honestly I've seen malware less invasive than the permissions that QMUNITY asks for.


Second problem (as if those above wasn't bad enough):

It uses Facebook login authentication.

Really!? Do you want Facebook to know where you went, more than it already knows? To be able to tagret the users even more finely?

Looking at what QMUNITY calls:

Facebook Ad network.

A payment platform?

Facebook activity.

Great, so now we're having over our Facebook account to MBKS.


Third problem:


Google Games API? Is QMUNITY expecting to sell in-app purchases?

Hooking into the Google Fit API, to get information on body vital signs for those who use a Smart Watch. If this was part of the app functionality, it is not made known to the user.

4th problem:

The actual website of the app itself:





The text where it says Terms of Use and Privacy Policy don't link to their, well, Terms of Use and Privacy Policy!

In fact, you have to dig for it, and find the actual link to the Privacy Policy: https://web.qmunity.app/mobileapp_privacypolicy_terms.html

Which neatly segues into...........

5th problem:

Quote:
This Privacy Policy does not apply to the third-party online/mobile store from which you install the Application or make payments, including any in-game virtual items, which may also collect and use data about you. We are not responsible for any of the data collected by any such third party.
Why is a contact tracing app talking about 3rd parties? Much less payments and in-game virtual items?


Quote 2:
Demographic and other personally identifiable information (such as your name, contact number, identification card number, email address, images, face data for facial recognition purpose) that you voluntarily give to us when choosing to participate in various activities related to the Application such as but not limited to creating a QMUNITY account, checking in to a location, giving feedbacks, and responding to surveys. If you choose to share data about yourself via your account or other areas of the Application, please be advised that all the data you disclosed in these areas is accessible to anyone who accesses the Application.
So, all the pictures in my phone? Forcing the user to do facial recognition? As part of the condition of using QMUNITY?


Quote 3:
The Application may by default access your Facebook basic account information, including your name, email, gender, birthday, current city, and profile picture URL, as well as other information that you choose to make public. We may also request access to other permissions related to your account, such as friends, check-ins, and likes.
So now we're giving MBKS our burthdays, profile pictures, friend list, and "likes".

How does this help contact tracing exactly?


Quote 4:
Device information such as your mobile device ID number, model, and manufacturer, version of your operating system, phone number, country, location, and any other data you choose to provide.
The unique ID of the phone, OS version, location, and "any other data you choose to provide". I presume that includes my cat photos?


Quote 5:
Collected face data will be used for facial recognition purposes in the checking-in process of premises with installed camera and thermal scanner. 

Deliver targeted information regarding the Application to you

Generate a personal profile about you to make future visits to the Application more personalized
Well, if facial recognition is a functionality of QMUNITY, it is very well hidden. Also, targeted informtion? How is this even part of contact tracing?


Quote 6:
We may share your information with our affiliates, in which case we will require those affiliates to honor this Privacy Policy. Affiliates include our parent company and any subsidiaries, joint venture partners, or other companies that we control or that are under common control with us.

Who are the affiliates/joint venture partners/subsidiaries? Who will MBKS share the data with? If I set up a RM2 company to do analytics, will they give me the data?


Quote 7:
We are not responsible for the actions of third parties with whom you share personal or sensitive data, and we have no authority to manage or control third-party solicitations.
You acknowledge that such transfers may occur and that the transferee may decline honor commitments we made in this Privacy Policy.

Right. So MBKS has the right to sell any data collected by QMUNITY,  but no responsibility. Apparently we should trust this app now?


Quote 8:
All data collected are stored in the Google server is Singapore.

But the app and website says that the QMUNITY solution is "Powered by Huawei Cloud". So is the data with Google or Huawei? Who has jurisdiction over the data collected?

The whole Privacy Policy has no mention of Huawei at all. So which one is it? Or does the QMUNITY team not know where their data is stored?

At least the COVIDsafe tracing app makes a passing referencing to the fact that data is stored in AWS.

Even the privacy policy has so many problems.



Post-script

I'm aware of one Pierce Wong circulating a Facebook post on QMUNITY, and throwing around Reader's discretion is advised like some kind of charm.

I don't know who this "Pierce Wong" is, nor do I agree with many of his statements. I have not seen anything in QMUNITY that "reads your input over other apps installed on the same device including exploits of intercepting user input into any fields including passwords (confirmed by firewall filter rules to detect attempts to login to my Maybank App using a test credentials)"

Also, the statement "The google account was compromised a day after installation (this morning) when someone attempted to log in from a remote NordVPN node. I have 2FA enabled on the google account that has a confirmation number not listed as device service number" makes no sense. If the Google Account was deleted, how can he receive a 2FA notification that "someone attempted to log in from a remote NordVPN node"?

Finally, his claim that "An attempt was made on my facebook with jpg code insertion through Chrome's graphical engine" is novel. I have never heard of an "jpg code insertion through Chrome's graphical engine" attack.

And I'm aware of stegosploiting and hiding malware in EXIF metdata in images

If "Pierce Wong" has found a bugsecurity vulnerability in Facebook/Google Chrome he's welcome to submit it to the bug bounty. He might even make some money and have a CVE in his name.


So MBKS was correct to lodge a police report?

No.

You don't make friends my lodging a police report alleging slander ("fitnah").

You don't improve QMUNITY by lodging police reports when there are valid concerns on the permissions QMUNITYrequest for in Android.

Trust is not built by threatening people.

If MBKS wants to increase the takeup of the QMUNITY app, they would do worst than to respond to feedback rather than trying to bring the force of a state slamming onto individuals.

Monday, May 18, 2020

Post script: Sarawak Covid Trace app

On top of the Gerak Malaysia, MySejathera, MyTrace (federal) apps, now SMA and SAINS have made their own thing with COVID Trace.

I know it is Malaysia, but there has been very little scrutiny of the app's by the Malaysian government (Gerak Malaysia, MySejahtera, MyTrace), and personally it is a typical case of the left hand not knowing what the right hand is doing.

(Gerak Malaysia was developed by the MCMC, MySejahtera was developed by the Ministry of Health, and MyTrace was developed by the Ministry of Science, Technology and Innovation)

In Australia there is only one app, one central website. (www australia.gov.au has been repurporsed as a COVID19 information hub)

Just different states with different rules doing different things

Taking apart the Sarawak Covid Trace app for Android


Source: https://www.newsarawaktribune.com.my/download-covidtrace-app-for-contact-tracing/

On 15 May 2020, Local Government and Housing Minister Dato Sri Dr Sim Kui Hian announced that Sarawak has decided to release their own contact tracing app, imaginatively called COVID Trace.

    My interest was piqued by this line in an article on the Borneo Post:



    Surely they can't be broadcasting mobile phone numbers in the clear?!

    So I decided to have a look.

    Foreword:

    This is a very rough first cut of taking apart the Sarawak Covid Trace app to see what it does (and doesn't) do. I am no Android developer, and by no means is this complete or comprehensive.

    Also, this post does not seek to:
    • Discover bugs in the app, be they functional or technical
    • Attempt to find security vulnerabilities
    This is purely to see if the app actually does what it claims to do based on public pronouncements, and what it actually does.

    Also this only covers the Android version of the app. I have not looked at the iOS version.

    It would be very helpful if SAINS and SMA actually published the source of the COVID Trace app, similar to what Australia has done with their COVIDSafe contact tracing app.


    Version:

    The version that I grabbed off the Google Play Store was marked version 1.0.0, uploaded on 12 May 2020. The hash of the APK that I pulled aprt is as follows:

    covidtrace_1.0.0.apk

    SHA-256: 931876caf1e61707ba8fdb0b67a2ddf5b432bf5e173d29f49640558f8c426209

    SHA-384: 704e92143362ad205cea6f2358ed3d0cd0d2be3bbea02accfca001f970113637514102d05665ee94da13ad6f58a8cdad

    SHA-512: e12fd9786ce4ee5dbb5ce89309cd49a76b65fcb212a6f30ef81d7a5976568695a9d21778f7a785861a016ac2003bf0404156827462f4ff9304a75e921ccad1f5


    I used JADX v1.1.0 to decompile it, and started poking around.


    What does it transmit?

    A cursory glance of the code confirms my suspicions: Sarawak COVIDTrace is based off the Singaporean OpenTrace code base, which is the basis of their Trace Together app.

    This is no bad thing: reusing good{ish}/better code is better than creating bad code from scratch

    I am pleased to say that Dr Sim is incorrect when he says: "this app can automatically detect and get the phone numbers of people within three metres around the handphone user."


    Note the code has references to Open Trace

    The only thing that the Sarawak COVID Trace app transmits is the power level of the Bluetooth probe (setIncludeTxPowerLevel), the random(ish) identifier that is generated (pUuid), a field that says it is the COVID Trace app, and the phone model (addManufacturerData)

    It explicitly exudes the phone name, by setIncludeDeviceName(false), so it wouldn't record "Fatimah's phone", "Tan Ah Beng OnePlus" etc

    In laymen's terms, what the probe sends out is:

    - The phone model (eg. Iphone 7, Xperia XZ1)
    - A randomly generated ID for the user (eg. fn67345443)
    - A field that says it is the COVID Trace app (to distinguish it from other Bluetooth devices like bluetooth headphones, your Google Speaker etc)
    - The transmit power level of the Bluetooth radio

    That is it.

    AFAIK the Sarawak COVID Trace app doesn't use the phone telco metadata. On the server side it might, but deassembling the app isn't going to show us or otherwise.


    What does it receive?

    It has a filter that only receives probes from the Sarawak COVID Trace app. So if there is another person using the Singaporean Trace Together app, it wouldn't record the intreaction with the person only using the Singaporean Trace Together app.



    On the receiving side, this is what is stored on the phone:
    • The date (in unix time)
    • The version of the Tracing protocol (v1 in this case)
    • The UUID (generated by the phone)
    • A "message" field (which is to announce that it is the Sarawak app)
    • The model of the phone sending the probe
    • The model of the phone receiving the probe (in this case I've been in contact with an iPhone user)
    • And the signal strength of the Blutetooth broadcast (RSSI, txpower)
    And this is what the government will receive from the uploaded data.

    The data is stored in a SQLite database it seems. 


    How does it submit the data?

    Similar to the Singapore Open Trace source code, the user needs to actually tap something to upload the data. There is no continous stream of data calling back to SAINS/SMA.



    When the upload is triggered by the user, it is sent to https://firebasestorage.googleapis.com. So that's where it is being sent to.

    The Australian COVIDSafe app had controversy, as it sends the data to device-api.prod.lp.aws.covidsafe.gov.au, aka AWS (Amazon Web Services). There was (and still is, if I may add) concern about data sovereignty.


    Source: https://covidtrace.sarawak.com.my/faq.html

    One thing that I found interesting, and that is not in the code but in the official FAQ, is that to upload the close contact data, is that the code to upload is not provided to the user over SMS to their number, but provided by the Department of Health officer.

    A bit of an out of band verification.

    An improvement, security wise, from the Australian version, where the person taps to upload their close contact data, they get sent a SMS, enter the code, and if it matches, then the upload task starts.

    I suppose the problem is how do you verify that the person is actually a Department of Health officer.......?


    Security of collected data

    One thing I will say is that the  Sarawak COVID Trace app doesn't allow other applications to access its store, so unless the phone is jailbroken, other apps can't access the tracing data stored in the Sarawak COVID Trace app.



    In laymans terms this means WhatsApp, Facebook etc, installed on your phone, cannot access the data in SarawakCOVID Trace.

    At least they did get this right.



    Identifying

    Unlike the Australian COVIDSafe app, the Sarawak COVID Trace app doesn't seem to cycle the UUID in intervals. (Every 2 hours in COVIDSafe, albeit imperfectly) The UUID is initialised at install, and the same UUID seems to be used as long as the app is installed.

    The thing is that the UUID is initialised at install, so uninstalling the Sarawak COVID Trace app and reinsalling it will generate a new and different UUID. So the UUID is not fixed to the phone (ie. getting the same UUID inspite of uninstalling and reinstalling the app, resetting the phone etc)

    When a person signs up with the COVID Trace app, their phone number is required to be entered. A SMS is sent to the number and as a one-time code sent.

    Once the verification is complete, that is when the app matches a phone generated UUID to a phone number.

    Only when a a person is:

    1) Confirm to be infected; and
    2) Consents to the data in the COVID Trace app being uploaded; then
    3) The process is to match the UUID (A randomly generated ID for the user) with a mobile phone number, and start picking up the phone and calling people


    Historical data, and not actually deleting after 21 days

    Another part of the article caught my eye:


    Source: https://www.theborneopost.com/2020/05/15/swak-comes-up-with-covid-trace-app-public-urged-to-utilise-it-dr-sim/

    That's may be what Dr Sim says. However I can't find anything in the code that actually deletes the contact probe details after any timeframe, let alone 21 days.

    One concern I have of the Sarawak COVID Trace app is that it doesn't delete the contact data. The Australian one deletes contact data after 21 days, so the phone doesn't store data that can be used to generate a historical running record of who you met with.

    While not a smoking gun, if I can't find anything in the code where there is a job to delete data after twenty-one days after looking for 20 mins, I'm going to say that more likely than not that Sim's statement, that "information gathered will be stored on your handphone for 21 days", may not be technically accurate.

    I don't want to be harsh on Dr Sim: he is not a tech person, no one is expecting him to vet the code, and he relies on what he is told.

    But I think it is fair to call out when the app doesn't do what the public pronouncements say it does.

    If anyone can find a regular process that deletes data older than 21 days I would be very much interested. 


    Calling back to Google Analytics?




    Another concern I have is that the Sarawak COVID Trace app calls back to Google (Advertisment) Analytics, without a clear indication on why it does so.

    I get that SAINS/SMA may want to get analytics on how many people who downloaded it are actually using it, how often, how long, do they kill the background process or not, but this data, and call back to Google, can be linked with the phone and used for custom ad targeting.

    IMO, this should NEVER be in a contact tracing app. Any contact tracing app should not be calling back to Google, much less Google Analytics.


    Claims vs code


    Source: https://covidtrace.sarawak.com.my/

    From what I see in the code vs what they claim on their official site:

    1) Yes, encounter history is stored locally, and not a ongoing stream to a remote server.

    2) It doesn't write GPS coordinates to the database; however it has code to get (but not store) GPS coordinates. No clear reason why it is there: if it is for future use this should be mentioned.



    3) The only PII collected is the mobile number: largely true. It doesn't ask for name or postcode or age range, which the Australian app does (albeit there is no obligation to provide correct information; my name is now Yui, I'm aged 18 - 25, and my postcode is 6969 #totallyMature)

    4) As mentioned above, the only thing that it broadcasts is a randomly generated UUID, phone model, and characteristics of the broadcast power

    There is debate whether a phone model with a static UUID can be considered unique and identifiable, but overall point 4 holds true

    5) As mentioned, subject to the phone not being jailbroken, other 3rd party apps are not allowed to access the data in Sarawak COVID Trace. However, there is the concern of the code for Google Analytics; and can be used to profile who has and who hasn't installed the app.

    6) We can only trust that they delete the data from their systems on their end once it is used. As for deleting the data on the phone, once the app is uninstalled the tracing data will be deleted.

    The issue of data only being kept on the phone for 21 days is still very much unresolved, and I really can't find any code that actually does it!




    Few concerns specific to Sarawak COVID Trace off the top of my head:


    1) The "data is only kept for only 21 days" claim: is not reflected in the code. Long term, it can be used to make a social network graph of who you met in person, assuming all parties are using the app. Privacy considerations.

    2) Use of Google Analytics: still unexplained, and should NOT be used (potentially Google can profile who is using contact tracing apps even if their other services in the phone can't access the app data)

    3) Data sovereignty: how happy (or otherwise) are people sending their data to Google (Firebase)? Probably an academic question for people using an Android phone without a custom de-googled ROM, but Apple and custom ROM users may have other thoughts

    4) How long will the uploaded data be stored? Who can access and use it? Are there limits on who can it be shared with?

    In Australia they rammed through legislation in Parliament to say that it can only be accessed by the (Australian) Department of Health, can't be used by police and security agencies, can't be use in court for criminal matters, data to be deleted "When the pandemic ends" (so, never), having an independent auditor for data access oversight, and making it an offence to force people to install COVIDSafe.

    5) The (reverse engineered) code is not obfuscated, so that is a good one in my books. However the objects and classes are all over the place, and not necessarily intuitively named.

    It works, but the code readability is not as easy as the Australian version.

    6) Somewhat related to my 2nd point above, no clear reason in the code why the app asks for Google Play Store Install Referrer API permissions.  Any app IMO should only require the bare minimum permissions. The Australian version works without asking for Google Play Store Install Referrer API permission.

    7) It does actually hijack any battery optimisation rules, prevents the phone from sleeping. While not a criticism per se, (it needs that to do its job) something to keep in mind.

    The Australian version of the app at least tries to adhere to the battery optimisation rules.

    8) In 2020, certificate pinning should be used, with the certificates on what it can connect to, put in the app. The Australian COVIDSafe app actually comes with certificate ke pinning, so it can only communicate with the server that it should only be communicating to. So hijacking DNS and a LetsEncrypt certificate MITM attack shouldn't be successful.

    9) The number of ciphersuites that it can use is IMO unnecessarily large. It is 2020: TLS 1.0 and 1.1 should not be used. I would enforce it to use TLS 1.3 only if I had my way; but acknowledge that TLS 1.2 is required for backwards compatibility.

    But even in TLS 1.2, the ciphersuite list should be trimmed: no 3DES, no SHA-1, GCM mode over CBC mode, with Forward Secrecy.


    (If anyone needs guidance on ciphersuites I'm more than happy to provide~!)


    Omake


    There is a little regional flavour in the io.bluetrace.opentrace.streetpass.StreetPassWorker object 😅😄



    Final words

    After all this, I think it is important to not miss the bigger picture: no app, no technology, is going to be the silver bullet.

    The app is only a aid for contact tracing: it is not the authoritative source of everyone that the person has had contact to.

    Nothing beats picking up phones, walking pavements (well, not that we have any in Malaysia), physically meeting people, to do contact tracing, to find people who may have been infected, and isolate them.

    Friday, May 08, 2020

    On another note Re. Japan Expo Malaysia 2019


    Source: https://twitter.com/Bas4ever1/status/1154740751332327424

    Probably the best bit.

    Translation: [REPO] 190727 Japan Expo Malaysia 2019

    Translator foreword: This is a rare field report from Japan Expo Malaysia 2019. Original langauge is in Taiwanese Mandarin; decided to translate it into English to keep my language skillset. Also some pretty good pictures.

    The only thing that is mine is the English translation. The original text and pictures remain the ownership of the original writer/photographer.

    Also, Riona <3 br="">

    #################################################################################






    寫repo這種事是拖不得
    但從出生以來,寫文章就不是擅長的事情
    拖到現在,也只能憑印象寫一些當時發生的事情了

    I shouldn't be dragging out to write a repo
    But since birth, writing essays has not been my strong point
    Having delayed writing to this point, I can only write anout my impressions during that time

    -------------------------------------------
    2019/07/27
    出演名單: チームA 向井地美音
    チームB 谷口めぐ
    チーム4 岡田奈々
    チーム8 坂口渚沙、岡部麟、小栗有以、

    活動場所: Pavilion Kuala Lumpur
    Event location: Pavilion Kuala Lumpur

    --------------------------------------------

    因為本人懶惰不喜歡距離移動
    且為了方便活動當日一早搶百貨公司開門營業時
    搶在表演舞台最前排觀看演出
    就不加思索地選擇會場旁的hotel住一晚

    As a lazy person I don't like moving around too much
    To facilitate the events of the day I wanted to make my way to the department store [Pavilion Kuala Lumpur] first thing in the morning
    To get the front most spots in front of the performance stage
    Without too much planning I chose to stay at the nearest hotel to the venue

    因為百貨公司早上十點開始營業
    早上八點懶洋洋地
    下樓吃早餐
    結果還沒進入餐廳門口
    就見到みーおん與なぁちゃん已經吃完早餐準備上樓
    當下瞬間睡意全消

    Because the department store [Pavilion Kuala Lumpur] only opens its doors at 10am
    At 8am on the day, lazily made my way downstrairs for breakfast
    Before even going near the entrace of the hotel restaurant
    Saw Mion and Naa-chan leaving the restaurant, having finished their breakfast and heading back up [to their hotel room]
    At that point all my sleepyness disappeared

    進入餐廳後
    開始找尋有沒有其他成員身影
    結果自己左手邊兩桌外
    出現野生且正在細細品嚐的早餐的 ゆいゆい
    終於可以嘴"與自己推的偶像共進早餐"這件事情一輩子 wwwww
    歡樂的時光在ゆいゆい吃完早餐後
    原以為這個酒店給我的驚喜只有這樣

    After entering the hotel restaurant
    I started looking for other members who may be around
    Spotted 2 tables away from my on my left
    Was a in the wild yuiyui having a tasty breakfast
    I can finally cross off "Having breakfast with an aidoru" in my bucket list wwwww
    After looking at yuiyui finish her breakfast
    I thought that this was the only surprise that this hotel that I was staying had for me

    沒想到辦理退房時
    又在大廳碰見野生的六人剛從會場彩排完
    準備上樓回房休息

    On my way back to my room
    Spotted the 6 members in the wild at the lobby returning from rehersal
    Heading back up to their room to rest

    參加這種非劃位活動
    只能說卡位要快. 狠. 準.

    To be able to "participate" in this non-offical activity
    I can only say that all the cards lined up without any thought

    AM10:00百貨公司準時開門
    只見熱情的日本粉絲
    不管三七二十一就直接往前衝
    連會場預先架設動線規劃的紅龍都被踹飛了wwwww

    On the dot at 10am the department store opened
    The only people there were the passionate Japanese fans
    Without hesitation making a beeline for the stage front area
    Even the red rope used to act as a guide for crowd control was ignored and pushed away wwwww

    -------------------------
    拼盤式偶像表演-漫長地等待
    -------------------------
    Assortment of aidoru performances in between waiting for the main act

    直至活動開始前
    While waiting for the main act to begin

    前チーム8成員濵松里緒菜
    較先上台演出 依稀記得第一首是純舞蹈表演
    然後接下來才是有拿麥唱

    Was former チーム8 member 濵松里緒菜
    From the recesses of my fading memory, it was a pure dance performance/number
    Only the 2nd performance did she have a microphone holding singing display





    然後玩猜拳贈送紀念品時間
    After that was a guessing game [with the fans] and a souvenir time



    Riona 幾乎是全英文與現場觀眾互動
    不愧是以前T8英語擔當wwwww

    Rionna interacted with the audience entirely in English
    As expected as the English speaker representative while in T8 wwwww

    ---------------------------------------
    快到AKB48表演時間
    人潮已經快把會場擠爆
    原本卡位在第二排
    瞬間莫名其妙被解壓縮插隊到第三排去了

    As the time for AKB48's performence got closer
    The crowd in the venue got more
    Originally I was in the second row from the stage
    But somehow the position I held became the 3rd row from the stage

    而AKB48 不愧是你可以面對面見到的偶像
    並不是從舞台正前方進場
    而是從百貨公司門口
    也就是觀眾的正後方走進表演舞台 =口=
    幾乎全場的人都可以面對面的接觸惹

    As for AKB48, they are after all supposed to be the aidoru's that you can meet
    Not just as audience at the feet of the stage
    But the people walking in from the entrance of the department store
    The people walking around the ball at the back of the stage
    Almost everyone in department store can become the audience

    最早預先架設紅龍所騰出的走道
    一早就被日本美女踹飛 www
    一開始就失去阻隔功效 就收了起來

    The red rope in front of the stage providing a first row division
    Had been completely disregarded by beautiful Japanese girls www
    With the red tape barrier's purpose lost, it was put away

    因此為了給從後方進場的成員開路上舞台
    與保持粉絲與成員的安全距離
    四周的保全與工作人員開始推擠觀眾
    結果現場亂成一團

    To allow the members to enter onto the stage
    And to keep the seperation between the members and their fans
    The security detail and event staff began to push the audience from all corners
    Causing the scene to be one big chaos

    M01 ヘビーローテション

    場面非常混亂 非常混亂 非常混亂
    幾乎都背對成員 完全沒辦法轉身
    且仍在與各方勢力推擠中wwwww

    The floor had become overwhelmed with chaos
    With the members behind me, it was impossible to even turn back to look
    As there was forceful pushing from all directions wwwww

    M02 希望的リフレイン

    因為在海外
    所以call聲不像在日本一樣熱烈
    大部分的人也都很認真拿著手機與相機拍著台上的成員
    這時候要喊call 也顯得很奇怪?

    As this is an overseas performance
    The [fan chant] calls are not as forthcoming as the Japan performances
    Most of the audience at this point was using their phones and cameras seriously to record the members performing on the stage
    To do the [fan chant] calls at this moment would be weird and not fitting with the atmosphere


    Naa-chan


    Soukantoku


    The 3 Team 8'ers


    Rinrin and yuiyui's brightness


    Rin-chan


    Nagisa-chan


    Megu

    M03 #好きなんだ

    前面都站在另一方向的有以 終於站在我面前惹
    第一次看到舞台上的生人 ! 不得不說 "有以好可愛啊"

    Those standing in the front row were facing yuiyui. Finally she was standing in front of me
    My first time seeing her in person! It is impossible to say "Yui is very cute"





    MC1

    這個環節
    印象中主持人問成員對馬來西亞印象如何?
    然後六個成員簡單自我介紹+一句問候的馬來語?

    In this breather
    I have the impression that the MC asked them members ther impression of Malaysia?
    And I think they had their self-introduction + one phrase in Malay?







    Irregardless, it was a good time for photo taking


    M04 言い訳Maybe

    這首有以還是在面前 兩萬年閃閃發亮
    還是那一句 "有以好可愛 "

    Yuiyui was the center for this song, with all 20,000 years of shinning
    And of course, "yuiyui is very cute"

    MC2

    抽禮物環節
    主持人一直喊拿到簽名毛巾的粉絲 今天走不出這個大門wwww

    Lucky draw for fangift [session]
    The MC quipped that those fans who got a signed towel would probably not be able to walk out in one piece wwww







    M05 恋するフォーチュンクッキー

    只要聽到這首歌 十之八九就代表準備結束惹
    With this song, there is the 90% probability that the session is coming to an end




    半小時的時光很快就過去惹 T_T
    Half an hour went by very quickly T_T


    可愛的ゆいゆい
    Cute yuiyui

    後記:

    有以好可愛 有以好可愛 有以好可愛
    當時為了想拍ゆいゆい特別殺去馬來西亞
    想說不知道這機會過了
    不知道還會多久才能再看到以及再拍到ゆいゆい
    沒想到兩個多月後 又出現在我面前惹wwwwww

    My motivation for coming to Malaysia was to capture yuiyui
    As I didn't want to pass on this opportunity
    Who knew when was the next opportunity to do so
    As it turned out, barely 2 months plus later, she appeared in front of me again wwwwww


    以機票與住宿來說 花不到一萬元
    卻可以超近距離觀賞偶像
    真的是CP值爆表的一趟旅程wwwww

    In terms of plane ticket and accommodation costs, came up to under TWD 10,000
    But all for the ability to watch aidoru's up close
    It was good value

    <感謝閱讀>



    Source: https://www.ptt.cc/bbs/AKB48/M.1587141676.A.E56.html