Contact tracing apps, contact tracing apps everywhere.
So the Sarawak State Government has decided to promote QMUNITY, a contact tracing app created by MBKS.Essentially, it is a "where I've been" recording solution. Call it an app, put a QR code, and people think its "new".
So, what permissions does ask for in Android?
There are so many things wrong with this list of application permissions. How did MBKS ever think this was even appropraite for an app, let alone a contact tracing app?
1) Why does a QMUNITY require access to the calendar of the phone? It's task is only to record who visited where at when. To see the details of the calendar, and to be able to modify it, is unnecessary overreach.
2) There is no reason for ANY contact tracing application to readthe contacts of the phone. Whatsapp is bad enough. How does reading the contacts of the user assist in contact tracing?
3) Why does QMUNITY need access to the phone functionality? Nothing in the application functionality asks for cellular voice capabilities.
4) Why does QMUNITY require access to phone storage outside its own container? Reading Photos/Media/Files and storage: how is QMUNITY being able to read the Photos/Media/Files and storage of the user able to assist in contact tracing?
5) How is QMUNITY needing access to the phone microphone able to assist in contact tracing?
6) How is knowing the "read phone status and identity" going to assist in contact tracing?
7) "manage document storage"? "change your audio settings"? "draw over other apps"? "control vibration"? "prevent device from sleeping"? "modify system settings"? "read Google service configuration"?
Honestly I've seen malware less invasive than the permissions that QMUNITY asks for.
Second problem (as if those above wasn't bad enough):
It uses Facebook login authentication.
Really!? Do you want Facebook to know where you went, more than it already knows? To be able to tagret the users even more finely?
Looking at what QMUNITY calls:

Facebook Ad network.
A payment platform?
Facebook activity.
Great, so now we're having over our Facebook account to MBKS.
Third problem:
Google Games API? Is QMUNITY expecting to sell in-app purchases?
Hooking into the Google Fit API, to get information on body vital signs for those who use a Smart Watch. If this was part of the app functionality, it is not made known to the user.
4th problem:
The actual website of the app itself:
The text where it says Terms of Use and Privacy Policy don't link to their, well, Terms of Use and Privacy Policy!
In fact, you have to dig for it, and find the actual link to the Privacy Policy: https://web.qmunity.app/mobileapp_privacypolicy_terms.html
Which neatly segues into...........
5th problem:
Quote:
This Privacy Policy does not apply to the third-party online/mobile store from which you install the Application or make payments, including any in-game virtual items, which may also collect and use data about you. We are not responsible for any of the data collected by any such third party.Why is a contact tracing app talking about 3rd parties? Much less payments and in-game virtual items?
Quote 2:
Demographic and other personally identifiable information (such as your name, contact number, identification card number, email address, images, face data for facial recognition purpose) that you voluntarily give to us when choosing to participate in various activities related to the Application such as but not limited to creating a QMUNITY account, checking in to a location, giving feedbacks, and responding to surveys. If you choose to share data about yourself via your account or other areas of the Application, please be advised that all the data you disclosed in these areas is accessible to anyone who accesses the Application.So, all the pictures in my phone? Forcing the user to do facial recognition? As part of the condition of using QMUNITY?
Quote 3:
The Application may by default access your Facebook basic account information, including your name, email, gender, birthday, current city, and profile picture URL, as well as other information that you choose to make public. We may also request access to other permissions related to your account, such as friends, check-ins, and likes.So now we're giving MBKS our burthdays, profile pictures, friend list, and "likes".
How does this help contact tracing exactly?
Quote 4:
Device information such as your mobile device ID number, model, and manufacturer, version of your operating system, phone number, country, location, and any other data you choose to provide.The unique ID of the phone, OS version, location, and "any other data you choose to provide". I presume that includes my cat photos?
Quote 5:
Collected face data will be used for facial recognition purposes in the checking-in process of premises with installed camera and thermal scanner.Well, if facial recognition is a functionality of QMUNITY, it is very well hidden. Also, targeted informtion? How is this even part of contact tracing?
Deliver targeted information regarding the Application to you
Generate a personal profile about you to make future visits to the Application more personalized
Quote 6:
We may share your information with our affiliates, in which case we will require those affiliates to honor this Privacy Policy. Affiliates include our parent company and any subsidiaries, joint venture partners, or other companies that we control or that are under common control with us.
Who are the affiliates/joint venture partners/subsidiaries? Who will MBKS share the data with? If I set up a RM2 company to do analytics, will they give me the data?
Quote 7:
We are not responsible for the actions of third parties with whom you share personal or sensitive data, and we have no authority to manage or control third-party solicitations.
You acknowledge that such transfers may occur and that the transferee may decline honor commitments we made in this Privacy Policy.
Right. So MBKS has the right to sell any data collected by QMUNITY, but no responsibility. Apparently we should trust this app now?
Quote 8:
All data collected are stored in the Google server is Singapore.
But the app and website says that the QMUNITY solution is "Powered by Huawei Cloud". So is the data with Google or Huawei? Who has jurisdiction over the data collected?
The whole Privacy Policy has no mention of Huawei at all. So which one is it? Or does the QMUNITY team not know where their data is stored?
At least the COVIDsafe tracing app makes a passing referencing to the fact that data is stored in AWS.
Even the privacy policy has so many problems.
Post-script
I'm aware of one Pierce Wong circulating a Facebook post on QMUNITY, and throwing around Reader's discretion is advised like some kind of charm.
I don't know who this "Pierce Wong" is, nor do I agree with many of his statements. I have not seen anything in QMUNITY that "reads your input over other apps installed on the same device including exploits of intercepting user input into any fields including passwords (confirmed by firewall filter rules to detect attempts to login to my Maybank App using a test credentials)"
Also, the statement "The google account was compromised a day after installation (this morning) when someone attempted to log in from a remote NordVPN node. I have 2FA enabled on the google account that has a confirmation number not listed as device service number" makes no sense. If the Google Account was deleted, how can he receive a 2FA notification that "someone attempted to log in from a remote NordVPN node"?
Finally, his claim that "An attempt was made on my facebook with jpg code insertion through Chrome's graphical engine" is novel. I have never heard of an "jpg code insertion through Chrome's graphical engine" attack.
And I'm aware of stegosploiting and hiding malware in EXIF metdata in images.
If "Pierce Wong" has found a bugsecurity vulnerability in Facebook/Google Chrome he's welcome to submit it to the bug bounty. He might even make some money and have a CVE in his name.
So MBKS was correct to lodge a police report?
No.
You don't make friends my lodging a police report alleging slander ("fitnah").
You don't improve QMUNITY by lodging police reports when there are valid concerns on the permissions QMUNITYrequest for in Android.
Trust is not built by threatening people.
If MBKS wants to increase the takeup of the QMUNITY app, they would do worst than to respond to feedback rather than trying to bring the force of a state slamming onto individuals.
No comments:
Post a Comment