AIRLINK 79.41 Increased By ▲ 1.02 (1.3%)
BOP 5.33 Decreased By ▼ -0.01 (-0.19%)
CNERGY 4.38 Increased By ▲ 0.05 (1.15%)
DFML 33.19 Increased By ▲ 2.32 (7.52%)
DGKC 76.87 Decreased By ▼ -1.64 (-2.09%)
FCCL 20.53 Decreased By ▼ -0.05 (-0.24%)
FFBL 31.40 Decreased By ▼ -0.90 (-2.79%)
FFL 9.85 Decreased By ▼ -0.37 (-3.62%)
GGL 10.25 Decreased By ▼ -0.04 (-0.39%)
HBL 117.93 Decreased By ▼ -0.57 (-0.48%)
HUBC 134.10 Decreased By ▼ -1.00 (-0.74%)
HUMNL 7.00 Increased By ▲ 0.13 (1.89%)
KEL 4.67 Increased By ▲ 0.50 (11.99%)
KOSM 4.74 Increased By ▲ 0.01 (0.21%)
MLCF 37.44 Decreased By ▼ -1.23 (-3.18%)
OGDC 136.70 Increased By ▲ 1.85 (1.37%)
PAEL 23.15 Decreased By ▼ -0.25 (-1.07%)
PIAA 26.55 Decreased By ▼ -0.09 (-0.34%)
PIBTL 7.00 Decreased By ▼ -0.02 (-0.28%)
PPL 113.75 Increased By ▲ 0.30 (0.26%)
PRL 27.52 Decreased By ▼ -0.21 (-0.76%)
PTC 14.75 Increased By ▲ 0.15 (1.03%)
SEARL 57.20 Increased By ▲ 0.70 (1.24%)
SNGP 67.50 Increased By ▲ 1.20 (1.81%)
SSGC 11.09 Increased By ▲ 0.15 (1.37%)
TELE 9.23 Increased By ▲ 0.08 (0.87%)
TPLP 11.56 Decreased By ▼ -0.11 (-0.94%)
TRG 72.10 Increased By ▲ 0.67 (0.94%)
UNITY 24.82 Increased By ▲ 0.31 (1.26%)
WTL 1.40 Increased By ▲ 0.07 (5.26%)
BR100 7,506 Increased By 12.9 (0.17%)
BR30 24,683 Increased By 124.5 (0.51%)
KSE100 71,971 Decreased By -80.5 (-0.11%)
KSE30 23,749 Decreased By -58.8 (-0.25%)
World

Qatar tracing app flaw exposed 1mn users' data

The glitch, which was fixed on Friday after being flagged by Amnesty a day earlier, made users' ID numbers, locatio
Published May 26, 2020
  • The glitch, which was fixed on Friday after being flagged by Amnesty a day earlier, made users' ID numbers, location and infection status vulnerable to hackers.
  • Despite insisting the unprecedented access was necessary for the system to work, officials said they would address privacy concerns and issued reworked software over the weekend.

DOHA: A security flaw in Qatar's controversial mandatory coronavirus contact tracing app exposed sensitive information of more than one million users, rights group Amnesty International warned Tuesday.

The glitch, which was fixed on Friday after being flagged by Amnesty a day earlier, made users' ID numbers, location and infection status vulnerable to hackers.

Privacy concerns over the app, which became mandatory for residents and citizens on pain of prison from Friday, had already prompted a rare backlash and forced officials to offer reassurance and concessions.

Users and experts had criticised the array of permissions required to install the app including access to photo and video galleries on Android devices, as well as allowing the software to make phone calls.

Despite insisting the unprecedented access was necessary for the system to work, officials said they would address privacy concerns and issued reworked software over the weekend.

"Amnesty International's Security Lab was able to access sensitive information, including people's name, health status and the GPS coordinates of a user's designated confinement location, as the central server did not have security measures in place to protect this data," the group said in a statement.

"While Amnesty International recognises the efforts and actions taken by the government of Qatar to contain the spread of the COVID-19 pandemic and the measures introduced to date, such as access to free healthcare, all measures must be in line with human rights standards."

More than 47,000 of Qatar's 2.75 million people have tested positive for the respiratory disease -- 1.7 percent of the population -- and 28 people have died.

Like other governments around the world, Qatar has turned to mobile phones to trace people's movements and track who they come into contact with, allowing officials to monitor coronavirus infections and alert people at risk of contagion.

The Etheraz app, which means "Precaution", continues to allow real-time location tracking of users by authorities at any time, the report added.

Security forces manned checkpoints across Qatar on Sunday to ensure use of the app alongside checking for use of masks, which are also compulsory in public.

"It was a huge security weakness and a fundamental flaw in Qatar's contact tracing app that malicious attackers could have easily exploited," said Claudio Guarnieri, head of Amnesty's security lab.

"The Qatari authorities must reverse the decision to make use of the app mandatory," he said.

Comments

Comments are closed.