Jay Harris Profile picture
Founder, pen tester and researcher @DI_Security. Runs @mcrgreyhats. #DevSecOps #radio #mobile #reversing #hardware. DMs open. He/him
May 5, 2020 11 tweets 4 min read
Have the #covid19 app and time to take a look. Not sure how much i'll do tonight because i'm sleepy.

First off, it looks like it only asks for a partial postcode when registering. Nice of them to provide one for me. It needs these permissions which is reasonable.
May 5, 2020 9 tweets 2 min read
(A thread) I started reading the NCSC document on the new #covid19 contact tracing app to be trialled in the Isle of Wight. Lots of interesting info. Until we have the actual app to look at, this is the best we can do.

I wanted to understand a couple of things: 1- What user data is collected?
The app asks users to enter their partial post code on registration. No other personal info is collected.

2- Are locations tracked?
No. The app uses BLE to detect proximity to other devices.