Older adults are particularly vulnerable to phishing attacks. Gamification has been shown to be less effective to develop confidence in distinguishing between genuine and phishing emails in this demographic. To overcome this, we present our novel, open source interactive training platform, Phish&Tips, based on a simulated inbox. Our multi-analysis approach provides comprehensive data that enables us to compare participant's self-assessed competence with their performance on the training platform. We present results based on pre- and post-training surveys, focus groups and the analysis of the training platform data (N = 37). Over half the participants demonstrated an improved understanding of various detection strategies and an increase in confidence in being able to interpret emails. However, these results were not evident in the analysis of the platform data. This disparity between participants' perceived knowledge and their performance on the platform highlights the challenges of applying their knowledge effectively.
OAuth 2.0 is a well-known protocol suite whereby customers of a web service can grant third-party applications access to their information (or resources) on said web service, all without handing over their long-term credentials. But what if the resources are encrypted? Should third parties get rights to decrypt them? We propose APEX: an OAuth-grounded suite of protocols which systematically augment delegated authorisation to allow refined third-party access to encrypted resources, while maintaining OAuth’s behaviour for any unencrypted resources. We also provide an implementation of APEX, showing its seamless integration with OAuth. On the formal side, we propose a generalisation of APEX (and OAuth) into a paradigm which we call restricted authorisation delegation (RAD). RAD is a model that lifts formal treatment from protocol to suites; and, it also stipulates the desirable requirements that delegated authorisation schemes should attain (including to enable access over encrypted resources). We also give a formal, cryptographic model that augments existing models in multi-party authorisation, authenticated key-exchange and access control. Finally, we use this model to prove that APEX formally attains all the properties of a restricted authorisation delegation (RAD) scheme, and discuss that OAuth 2.0 does not.
Electronic voting is a wicked problem: voters must only vote once, voting must be auditable, and votes must be permanently preserved—but they must also be anonymous. We examine the source code of a paperless Direct Recording Electronic voting system and find serious integrity and privacy issues. Those issues were reported to the relevant authorities and patched, but the underlying design issues remain.
Older adults are particularly vulnerable to phishing attacks. Gamification has been shown to be less effective to develop confidence in distinguishing between genuine and phishing emails in this demographic. To overcome this, we present our novel, open source interactive training platform, Phish Tips, based on a simulated inbox. Our multi-analysis approach provides comprehensive data that enables us to compare participant’s self-assessed competence with their performance on the training platform. We present results based on pre- and post-training surveys, focus groups and the analysis of the training platform data ( N=37) . Over half the participants demonstrated an improved understanding of various detection strategies and an increase in confidence in being able to interpret emails. However, these results were not evident in the analysis of the platform data. This disparity between participants’ perceived knowledge and their performance on the platform highlights the challenges of applying their knowledge effectively.
We define and formalise a generic cryptographic construction that underpins coupling of companion devices, e.g., biometrics-enabled devices, with main devices (e.g., PCs), in a user-aware manner, mainly for on-demand authentication and secure storage for applications running on the main device. We define the security requirements of such constructions, provide a full instantiation in a protocol-suite and prove its computational as well as Dolev-Yao security. Finally, we implement our protocol suite and one password-manager use-case.
Introduction: Sharing of health data for secondary uses such as research and public policy development is common. There are many potential benefits, but also risks if information about an individual's health record can be inferred. Studies show cautious willingness amongst the public to share health data for beneficial purposes, as long as they are confident in their data privacy and security. There has been relatively little research into whether the technical guarantees of privacy-preserving technologies are well understood by people asked to consent to sharing their data. Objectives: We sought to assess how accurately people understood the effectiveness of techniques for protecting the privacy of shared health data. Methods: We designed an online survey describing a data-sharing scenario motivated by medical research where data could be shared: raw (including identifiers), de-identified (using k-anonymity), aggregated, and differential privacy applied to aggregated data. Respondents were asked about willingness to share their data, and how likely it was that they could be identified. They were also asked for the meaning of 'de-identified' and whether they would agree to sharing information for 'not solely commercial' purposes, thus mirroring the consent language used by Australia's My Health Record system. Results: Our findings revealed substantial tolerance for researcher use of health data with consistent preference to share data when better privacy-preserving techniques were employed. This was not entirely consistent as slight preference was shown for aggregated data over differential privacy, despite differential privacy being objectively more secure. We conjecture this was because differential privacy and its benefits were not well understood. Similarly, respondents showed no consistent understanding of the term 'de-identified', indicating that this needs to be carefully defined in contexts that seek consent. Finally, many respondents who indicated a willingness to share for purposes that were 'not solely commercial' nevertheless rejected at least some specific scenarios that mixed research and commercial objectives, again indicating a possible gap in their understanding of the terms. Conclusions: We found overall preference for better privacy protection of data as a precondition for secondary use, but limitations in respondents' understanding of key terminology and the differing privacy guarantees of available techniques. Further effort is needed to word secondary data use consent policies to ensure public understanding of commonly used terms and methods, if genuinely informed consent for data sharing is to be gained.
Encouraging and supporting diversity and inclusion in computer science research communities is a critical issue for many reasons, including the ethical and robust design, delivery and publication of research that addresses real-world situations ranging from the use of digital tools in health to predictive policing to workplace hiring practices, just to name a few. One way to measure diversity is to apply analytical research methods to data sourced from the public domain for use in research. However, attempts to measure diversity using public data may themselves raise legal and ethical questions about the provenance of the data, research methods adopted, and treatment of diversity in the publication of results. This article interrogates the challenges of measuring diversity using public data, examining an illustrative case study framed around an academic research project at an Australian university using a public data set to identify gender representation in computer science communities. Employing a critical data governance perspective, we point to a range of ethical and legal concerns and recommend greater regulatory guardrails to better balance public interests in research and the privacy, data protection and other ethical interests of research subjects.
Even though passwordless authentication to online accounts offers greater security and protection from attack, passwords remain prevalent. Passwordless authentication adoption is impacted by the slow adoption of external hardware keys required to generate the security keys within the authentication protocol. We have developed a virtual WebAuthn authenticator in order to provide an extensible open source platform for understanding the associated standards of WebAuthn and CTAP2. Our authenticator provides secure software authentication for devices that do not have access to a physical hardware interface. Our authenticator also provides an alternative to an external physical hardware key and supports the use of a trusted platform module (TPM) on a device to generate the security keys within a WebAuthn protocol.
Developments in pervasive data collection and predictive data analytics are allowing firms to target consumers with increasingly precise personalised, behavioural and contextual advertising. These techniques give rise to new risks of harm in the attention economy by unduly influencing or manipulating consumers’ decision-making, and also by narrowing the product options visible and available to them. In many countries, the legal response to concerns about targeted advertising by algorithm has been focused on privacy protection and data rights. These are important initiatives. However, consent-based data rights are unlikely to provide a comprehensive or even adequate response to the risks of harm to consumers occasioned by the kinds of algorithmically targeted advertising that are now possible. This paper suggests that a suite of responses from the consumer protection toolkit are required to respond to the different manifestations of algorithmically targeted advertising. These include bans and warnings as well as making use of standard safety-net prohibitions on misleading and unconscionable/unfair conduct already in place in many jurisdictions.
We propose a protocol for verifiable remote voting with paper assurance. It is intended to augment existing postal voting procedures, allowing a ballot to be electronically constructed, printed on paper, then returned in the post. It allows each voter to verify that their vote has been correctly cast, recorded and tallied by the Electoral Commission. The system is not end-to-end verifiable, but does allow voters to detect manipulation by an adversary who controls either the voting device, or (the postal service and electoral commission) but not both. The protocol is not receipt-free, but if the client honestly follows the protocol (including possibly remembering everything), they cannot subsequently prove how they voted. Our proposal is the first to combine plain paper assurance with cryptographic verification in a (passively) receipt-free manner.
A false impression of technological panacea may see much needed interventions overlooked and may introduce unintended consequences and risks In the face of coronavirus disease 2019 (COVID-19) limiting free movement, experts are scrambling to mitigate the profound impact that the disease is having on our lives. For many countries, this approach involves increased testing, isolation, and education about hygiene practices until a vaccine is found. To varying degrees, without much evidence as to their efficacy, countries are turning to technology to solve some of the current challenges.1 Increasingly, smartphone applications (apps) are being contemplated for tracking proximity of people to determine possible sources of transmission, with elements of technological solutionism. Such technical solutions require trust, and without honest and clear information about the possibilities and limitations of technologies, an app's benefits may be undermined by low adoption, or conversely a false impression of a technological panacea may see much needed interventions overlooked. For example, the Australian Government's target of a 40% uptake of the COVIDSafe app may or may not be effective in helping to control the disease, while 60% uptake is supported by independent modelling from the United Kingdom.2 Furthermore, such summary statistics do not clarify to the public the wide range of other factors and assumptions that must be considered in predicting the app's efficacy. Much is being written about the different technological models and whether they trace, track and comply with privacy and human rights frameworks, including whether this information can, in fact, ever be anonymised.3 Fully effective anonymisation is unlikely when collecting data as granular as regular interaction with others in addition to age, gender and postcode demographics, as has been demonstrated by previous attempts to de-anonymise data.4 If these data are accidentally or deliberately linked with other datasets, such as births in hospitals or the public Myki public transport dataset,5 anonymity is virtually impossible to guarantee. Successful uptake of new technologies requires trust. When adoption is insufficient, collective benefits are not guaranteed. Civil society in the United Kingdom called for clear and comprehensive primary legislation to regulate data processing in symptom tracking and digital contact tracing applications, including with a strict purpose, access and time limitations.6 Such regulation may improve trust. Even when people are told of the limitations of technology, they may have magical thinking about its capabilities.7, 8 In early May 2020, the Australian Government furthered this magical thinking by direct messaging Australians that downloading the COVIDSafe app would help to keep people safe and ease restrictions, linking the two directly and potentially conflating the capability of COVIDSafe. Contact tracing apps may assist in manual tracing, in turn slowing the virus' spread, but usage of an app does not render the individual protected from infection nor does it guarantee successful tracking without intensive manual efforts. Yet statements by those in authority have made strained assertions about COVIDSafe, likening the use of the app to the use of sunscreen9 or a digital vaccine: "You could think about contact tracing as a digital vaccine with our contact data being the virtual antibodies".10 Such statements are incorrect representations of the app's capabilities.11 Even the technical details of the app are not immune from false messaging. For example, the app records all Bluetooth contacts, not just those that last 15 minutes or that are within 1.5 m. The filtering occurs after contacts are uploaded. Furthermore, there are some inaccurate statements on the official COVIDSafe website; for example, the frequently asked questions section states that "all information that is stored on the phone is digitally encrypted;" however, metadata, such as the device make and model for each contact, are stored unencrypted.12 Communication must be fact-based, transparent and consultative, any short term gains in support from the use of emotive and persuasive messaging may be undone when they are ultimately demonstrated to be false. The fundamental difference between centralised versus decentralised tracking is in who learns what. In the centralised approach, the central authority learns who an infected person has interacted with, whereas this does not occur in the decentralised system. Decentralised systems are no more challenging to implement but they better protect privacy. In a centralised approach (Box 1), such as TraceTogether (Singapore) or COVIDSafe (Australia): The above is a very high level description and there are many technical challenges in implementing such a system securely.13 In a decentralised approach (Box 2), as proposed by decentralised privacy-preserving proximity tracing (DP-3T), Covid Watch, Apple and Google: While there are variations in the details, in the decentralised approach, the central authority does not map identifiers to individuals. Although the distinction between centralised versus decentralised tracking may seem small, from a privacy perspective, there is a significant difference. In the case of COVIDSafe, the identifiers are generated and provided to the phone individually rather than as a daily batch: the central authority can monitor whether the app is being used in at least 2-hourly increments, and possibly as frequently as every 9 minutes, due to regular checks for new identifiers. Models reflect differing societal priorities. In Germany, where there are legal protections for both individual and group privacy, the decentralised app has been chosen. In fact, it has been suggested that a decentralised smartphone contact tracing system — as contemplated by DP-3T, Apple, Google, and governments across Europe — would be likely to comply with human rights and data protection laws. In contrast, a centralised smartphone system would pose a greater risk to fundamental rights and would require significantly greater justification to be lawful.6 Even when consent for central data collection has been sought, it is unclear what users are consenting to in the absence of fully open code that includes server-side code, a clear regulatory framework, and with omissions, such as the COVIDSafe's Privacy Impact Assessment and Privacy Policy failing to mention the collection of the devices' make and model.14 In comparison, Singapore's TraceTogether is based on the same codebase and its frequently asked questions section notifies of such data collection.15 Bluetooth Low Energy (BLE) is designed to be a low power communication technology, it was not designed to facilitate range finding. Accurately measuring the distance between two devices based only on the received signal strength is a challenge, with error margins often in the metres.16 The signal strength is relative not absolute, and thus, the scale of the reported values differ by manufacturer. Furthermore, the signal strength is influenced by many external factors, including the angle at which the device is held, whether it is in a pocket or a bag and any objects around or between it and the other device. Whether BLE can deliver the necessary accuracy remains an open question. While the use of Bluetooth avoids direct location tracking, many other risks remain. There are vast networks of Bluetooth beacons distributed around cities, which facilitate location tracking. Security advice is to disable Bluetooth when not in use. While the public might be expected to compromise for the common good, legislation could also move to limit Bluetooth beacons during the crisis. However, the Privacy Amendment (Public Health Contact Information) Act 202017 passed on 14 May provides no such protections.18 It provides an exemption to those accidentally collecting COVIDSafe data as part of a wider collection of non-COVIDSafe data. This appears to be aimed at protecting commercial tracking, rather than protecting privacy. Given the many risks of using technology, the contemplation of any technological solutions to alleviate the impacts of COVID-19 needs to be not only technical but also legal and social. Making the code open for audit provides some technical guard rails, much as providing open and transparent proof of test results ensures that no risks are overseen. But beyond technical questions there are also legal questions, including with whom the data may be shared. A recently published article refers to the multiple legal regimes potentially applicable to the app in Australia, as experts scramble to review the legal protections for individuals using COVIDSafe.19 Enacting emergency measures in the face of catastrophes is easy. Rolling back changes to technology, habits and even culture is far more difficult. If they are to be used, technological tracking solutions must have sunset clauses to ensure that human rights are protected. But even with sunset clauses, the large quantity of data collected are effectively out in the world, where they can be accessed and misused. Protections and limits for these data and their providers need to be contemplated before use, not only to protect individuals but also for group privacy. Increasingly, there is a risk of data being accessed by overseas agencies, which could have an impact on national security. It is vital that the technical, legal and social challenges are addressed in coordination. Any new legislation must be written within the context of existing technological practices, particularly around Bluetooth tracking. Likewise, where technical compromises are made, they must be justified to the public with clear, concise explanations, in a manner that is transparent and open to scrutiny. While many liberties have been curtailed during COVID-19, all modifications to existing rights are required, under law, to be legal, necessary and proportionate. These same standards apply to the use of technology. Legal protections need to be in place to ensure that rights are protected, including the right to privacy. Without sound legal protections and safeguards, tracing apps will not only fail but will embed values that may not be those that represent the society we wish to be. We thank David Watts and Vanessa Teague for their helpful comments. No relevant disclosures. Commissioned; externally peer reviewed.
Privacy protection legislation and policy is heavily dependent on the notion of de-identification. Repeated examples of its failure in real-world use have had little impact on the popularity of its usage in policy and legislation. In this paper we will examine some of the misconceptions that have occurred to attempt to explain why, in spite of all the evidence, we continue to rely on a technique that has been shown not to work, and further, which is purported to protect privacy when it clearly does not. With a particular focus on Australia, we shall look at how misconceptions regarding de-identification are perpetuated. We highlight that continuing to discuss the fiction of de-identified data as a form of privacy actively undermines privacy and privacy norms. Further, we note that ‘de-identification of data’ should not be presented as a form of privacy protection by policy makers, and that greater legislative protections of privacy are urgently needed given the volumes of data being collected, connected and mined.
Despite the benefits that the use of electronic health records (EHR) provides for doctors, other healthcare professionals and researchers, people have genuine privacy concerns that their data might be leaked or accessed by unauthorised parties. This paper investigates and compares security measures that are implemented in three countries namely Denmark, England and Australia, to protect EHR systems. A comprehensive analysis of literature (including official documentation of EHR in the three countries) was conducted to identify countermeasures related to the technologies, policies and human factors that implemented in Denmark, England and Australia to safeguard their EHR. The findings of this paper highlight the importance of adopting a more holistic approach where strong policies and practices are implemented, and cyber security awareness and training are provided to the users of the system. Such approach will address people privacy concerns and increase their trust in using EHR. The comprehensive analysis has revealed countermeasures implemented to protect EHR in three countries. It shows that more focus needs to be given to users training and awareness to prevent any human related security incidents.
Adopted by government agencies in Australia, New Zealand and the UK as policy instrument or as embodied into legislation, the 'Five Safes' framework aims to manage risks of releasing data derived from personal information. Despite its popularity, the Five Safes has undergone little legal or technical critical analysis. We argue that the Fives Safes is fundamentally flawed: from being disconnected from existing legal protections and appropriation of notions of safety without providing any means to prefer strong technical measures, to viewing disclosure risk as static through time and not requiring repeat assessment. The Five Safes provides little confidence that resulting data sharing is performed using 'safety' best practice or for purposes in service of public interest.
The subject of this report is the re-identification of individuals in the Myki public transport dataset released as part of the Melbourne Datathon 2018. We demonstrate the ease with which we were able to re-identify ourselves, our co-travellers, and complete strangers; our analysis raises concerns about the nature and granularity of the data released, in particular the ability to identify vulnerable or sensitive groups.
We present a very simple universally verifiable MPC protocol. The first component is a threshold somewhat homomorphic cryptosystem that permits an arbitrary number of additions (in the source group), followed by a single multiplication, followed by an arbitrary number of additions in the target group. The second component is a black-box construction of universally verifiable distributed encryption switching between any public key encryption schemes supporting shared setup and key generation phases, as long as the schemes satisfy some natural additive-homomorphic properties. This allows us to switch back from the target group to the source group, and hence perform an arbitrary number of multiplications. The key generation algorithm of our prototypical cryptosystem, which is based upon concurrent verifiable secret sharing, permits robust re-construction of powers of a shared secret.
The cryptographic weaknesses recently discovered in SwissPost's e-voting system are described in this article. We explain how they relate to security problems in other Internet voting systems and discuss the necessary principles for building trustworthy elections.
Electronic Voting Machines (EVMs) used in the 2019 General Elections in India were fitted with printers to produce Voter-Verifiable Paper Audit Trails (VVPATs). VVPATs allow voters to check whether their votes were recorded as they intended. However, confidence in election results requires more: VVPATs must be preserved inviolate and then actually used to check the reported election result in a trustworthy way that the public can verify. A full manual tally from the VVPATs could be prohibitively expensive and time-consuming; moreover, it is difficult for the public to determine whether a full hand count was conducted accurately. We show how Risk-Limiting Audits (RLAs) can provide high confidence in Indian election results. Compared to full hand recounts, RLAs typically require manually inspecting far fewer VVPATs when the outcome is correct, and are much easier for the electorate to observe in adequate detail to determine whether the result is trustworthy. We show how to apply two RLA strategies, ballot-level comparison and ballot polling, to General Elections in India. Our main result is a novel method for combining RLAs in constituencies to obtain an RLA of the overall parliamentary election result.