Skip to main content
QUICK REVIEW

[Paper Review] Short Paper: Privacy Comparison of Contact Tracing Mobile Applications for COVID-19

Mohamed‐Lamine Messai, Hamida Seba|arXiv (Cornell University)|Oct 7, 2020
COVID-19 Digital Contact Tracing7 references4 citations
TL;DR

This paper evaluates and compares the privacy properties of major contact tracing mobile applications for COVID-19, focusing on Bluetooth and GPS-based systems. It analyzes how design choices—particularly centralized vs. decentralized architectures—affect user privacy, concluding that decentralized, open-source models with strong anonymization and data deletion offer superior privacy protection compared to centralized or GPS-dependent systems with weak or no privacy safeguards.

ABSTRACT

With the COVID-19 pandemic, quarantines took place across the globe. In the aim of stopping or slowing the progression of the COVID-19 contamination, many countries have deployed a contact tracing system to notify persons that be in contact with a COVID-positive person. The contact tracing system is implemented in a mobile application and leverages technologies such as Bluetooth to trace interactions between persons. This paper discusses different smart-phone applications based on contact tracing system from privacy point of view.

Motivation & Objective

  • To analyze and compare the privacy risks inherent in various contact tracing mobile applications deployed during the COVID-19 pandemic.
  • To identify the primary sources of privacy threats in these applications, including health authorities, malicious developers, infected users, and hackers.
  • To evaluate how different technical designs—especially centralized vs. decentralized architectures—affect user privacy.
  • To assess the role of anonymization, source code transparency, and data retention policies in enhancing or undermining privacy.

Proposed method

  • The study conducts a comparative analysis of 8 major contact tracing applications, including TraceTogether, Aarogya Setu, AC19, StopCovid, Stopp Corona, Covid-Watch, PACT, and DP-3T.
  • Applications are evaluated based on predefined privacy criteria: use of Bluetooth or GPS, need for a trusted server, support for false claims, anonymization techniques, openness to source code, and data destruction policies.
  • The analysis focuses on threat vectors such as deanonymization by health authorities, surveillance by malicious developers, and data breaches by hackers.
  • The paper categorizes systems into centralized (server-dependent) and decentralized (peer-to-peer) models, assessing their respective privacy trade-offs.
  • Each application is scored on key privacy dimensions, including whether it uses random identifiers, stores data on servers, or deletes data after a set period.
  • The comparison is structured using a table that maps each app to its privacy-relevant properties, enabling direct contrast across design choices.

Experimental results

Research questions

  • RQ1How do centralized versus decentralized contact tracing architectures differ in their privacy implications for users?
  • RQ2To what extent do anonymization techniques and open-source status reduce privacy risks in contact tracing applications?
  • RQ3What are the main privacy threats posed by health authorities, malicious developers, infected users, and hackers in these systems?
  • RQ4How do GPS-based and Bluetooth-based systems compare in terms of privacy leakage and user tracking potential?
  • RQ5What role does data retention and deletion play in minimizing long-term privacy exposure?

Key findings

  • Centralized applications like Aarogya Setu and AC19, which rely on a trusted server and use GPS or unencrypted data, pose higher privacy risks due to centralized data storage and lack of anonymization.
  • Decentralized systems such as PACT and Covid-Watch, which do not require a central server and use anonymous identifiers, significantly reduce the risk of mass surveillance and data breaches.
  • Open-source applications like TraceTogether and Stopp Corona demonstrate better trustworthiness and transparency, reducing the risk of hidden tracking mechanisms by developers.
  • Applications that implement strong anonymization and delete data after a defined period—such as StopCovid and Stopp Corona—offer stronger privacy guarantees than those without such policies.
  • The use of GPS in applications like AC19 and Aarogya Setu increases privacy leakage and battery consumption, making them less suitable for long-term, large-scale deployment.
  • Even in systems with anonymization, users may still infer infection status through notification receipt, indicating an unavoidable privacy loss in the contact tracing model itself.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.