Anyways, I take this project to be a proof of concept. One would hope that governments will have healthcare professionals replacing the self-diagnosis step. * hope *
[1] https://github.com/CrunchyBagel/TracePrivately/blob/master/T...
Anyways, I take this project to be a proof of concept. One would hope that governments will have healthcare professionals replacing the self-diagnosis step. * hope *
[1] https://github.com/CrunchyBagel/TracePrivately/blob/master/T...
That's why this is a sample app and not the actual application that public health authorities will be using.
See below:
"A representative from Apple and Google's joint contact-tracing project said that their system similarly envisions that patients can't declare themselves infected without the help of a health care professional, who would likely confirm with a QR code." [1]
[1]: https://www.wired.com/story/apple-google-contact-tracing-str...
... now what? Someone has to aggregate that key (along with all the other flagged ones) somewhere, and then end users have to voluntarily choose to download the keys from that source and check for themselves if they came into contact with it. So you would have to get someone to accept your self reported positive key, and then convince a bunch of end users to trust that (apparently untrustworthy) data source.
I expect that most databases will require some sort of authentication from a healthcare provider or known laboratory before they will accept a key from an end user.
If the abuser took the effort to place a device and broadcast RPK for a while, then upload the Diagnosis Keys, I'm hoping Apple or Google have a way to validate the requests is from a legit device and thus abuser would have to have a lot of devices to game the system.