TL/DR: The A/G approach to contact-tracing is *different* from COVIDSafe, and has some public health costs (as well as privacy benefits). And the transition would involve a complete rewrite, with the new version not being interoperable with the old. 2/6
This is a big decision. Companies should refuse govt requests that risk privacy for public health if they can provide the same function with less risk to privacy, or if fundamental rights are at stake. But neither of those reasons applies here. 3/6
There are public health differences, and the determination and draft legislation (though it needs improving) protect fundamental rights. Decisions about how to weigh privacy against public health should be made by those we elect to make them, not by tech executives. 4/6
Even if you agree with Apple in this case, you should be concerned about such a huge decision being made by people who have zero accountability to you. And yes, I know our democracy #auspol has problems. But it's the best we've got. 5/6
Our article is based on what's publicly known now, including evidence given by DTA CEO last week, and Apple's framework API and API extension addendum. More transparency from all corners would be welcome. 6/6
https://developer.apple.com/documentation/exposurenotification/enexposureinfo describes what info can be extracted from app's that meet Gapple's Framework API. Only date, duration, signal strength, not exact time or to-whom exposed, data that COVIDSafe currently provides.
https://developer.apple.com/contact/request/download/Exposure_Notification_Addendum.pdf 3.4 is the most relevant part e.g. says that health authority can't link specific individuals to someone who has tested positive
According to this, the legislation being passed today would be redundant if we adopt the Gapple framework API. There would be no national data store, and basically no 'COVID App Data' to misuse.
Some folks are saying that there will be a workaround of some kind. I would love to see details! For my money, I think Apple should enable COVIDSafe to work properly, not require us to develop a new app that meets the current API.
You can follow @sethlazar.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled: