Schools and universities in the US they are divided on whether to open for the fall semester, thanks to the ongoing pandemic.
Albion College, a small Michigan liberal arts school, said in June that it will allow its nearly 1,500 students to return to campus for the new academic year starting in August. Classes would be limited in size and the semester would end by Thanksgiving instead of December. The school said it will test both staff and students as they arrive on campus and throughout the academic year.
But less than two weeks before students started arriving on campus, the school announced it would require them to download and install a contact-tracking app called Aura, which is said to help deal with any coronavirus outbreak on campus.
There is a problem. The app is designed to track the location of students in real time around the clock and cannot be waived.
The Aura app lets the school know when a student tests positive for the COVID-19 test. It also comes with a contact tracking feature that alerts students when they have come into close proximity to a person who has tested positive for the virus. But the feature requires constant access to the student's real-time location, which the college says is needed to track the spread of any exposure.
The school's mandatory use of the app has raised privacy concerns and prompted parents to petition to make using the app optional.
Worse still, the app had at least two security vulnerabilities only discovered after the app was implemented. One of the vulnerabilities allowed access to the app's back-end servers. The other allowed us to infer a student's COVID-19 test results.
The vulnerabilities have been fixed. But students should still use the app or face suspension.
Track and trace
Exactly how Aura was born and how Albion became its first major client is a mystery.
Aura was developed by Nucleus Careers in the months following the onset of the pandemic. Nucleus Careers is a Pennsylvania-based recruiting firm founded in 2020, with no apparent history or experience of creating or developing health care apps beyond a brief mention in a recent press release. The app was made in collaboration with Genetworx, a Virginia-based laboratory that provides coronavirus tests. (We asked Genetworx about the app and its involvement, but ProWellTech hasn't received a response from the company.)
The app helps students locate and schedule COVID-19 tests on campus. Once a student is tested for COVID-19, the results are fed into the app.
If the test is negative, the app displays a QR code which, once scanned, says the student is "certified" virus free. If the student tests positive or has yet to be tested, the student's QR code will be "denied".
Aura uses the student's real-time location to determine if he has come into contact with another person with the virus. Most other contact tracking apps use nearby Bluetooth signals, which experts say is more privacy friendly.
Hundreds of academics have claimed that the collection and storage of location data is detrimental to privacy.
In addition to having to install the app, students were told not to be allowed to leave campus for the duration of the semester without authorization for fears that contact with the wider community could bring the virus back to campus.
If a student leaves campus without authorization, the app will notify the school and the student ID card will be blocked and access to campus buildings will be revoked, according to an email to students, seen by ProWellTech.
Students are not allowed to deactivate their location and can be suspended and "removed from campus" if they violate the policy, the email reads.
Private universities in the United States such as Albion can largely set and enforce their own rules and have been likened to "shadow criminal justice systems - without any protection or power of a criminal court," where students can face discipline and expulsion for almost any reason with little or no recourse. Last year, ProWellTech reported on a Tufts University student who was expelled for alleged hacking, despite supporting evidence in her favor.
Albion said in an online question-and-answer session that "the only time a student's location data will be accessed is if they test positive or leave campus without following the proper procedure." But the school did not say how it will ensure that student location data is not accessed improperly or who can access it.
"I think it's more disturbing than anything else and it caused me a lot of anxiety about going back," a senior student, who asked not to be named, told ProWellTech.
An "urgent job"
An Albion student wasn't convinced the app was safe or private.
The student, who asked to pass by her Twitter handle @ Q3w3e3, decompile and analyze the apps on the side. "I just love knowing what the apps are doing," he told ProWellTech.
Buried in the app's source code, it found hard-coded secret keys for the app's back-end servers, hosted on Amazon Web Services. He tweeted his findings - carefully drafted to prevent misuse - and reported the issues to Nucleus, but received no response.
endpoint: "https://t.co/a5j4nvu5nQ",
accessKeyId: "[REMOVED FOR REASONS]',
secretAccessKey: "[REMOVED FOR REASONS]',
region: "us-west-2"- xXx_ANT1FA_5C3N3_QU33N_xXx (@ Q3w3e3) 12 August 2020
A security researcher, who asked to pass by his handle Guild, he was watching the tweets about Aura. Gilda also dug into the app and found and tested the keys.
"The keys were basically" full access, "" Gilda told ProWellTech. She said the keys - since they changed - have allowed her to access the app databases and cloud storage where she found patient data, including COVID-19 test results with names, addresses and dates of birth.
Nucleus released an updated version of the app the same day with the keys removed, but did not recognize the vulnerability.
ProWellTech also wanted to look under the hood to see how Aura works. We used a network analytics tool, Burp Suite, to understand the network data in and out of the app. (We've done this a couple of times already.) Using our spare iPhone, we signed up for an Aura account and logged in. The app normally invokes itself in recent COVID-19 tests. In our case we didn't have any and therefore the scannable QR code, generated by the app, stated that I had been "denied" authorization to enter the campus - as was to be expected.
But our network analysis tool showed that the QR code was not generated on the device but on a hidden part of Aura's website. The web address that generated the QR code included the Aura user's account number, which is not visible from the app. If we increased or decreased the account number in the web address by a single digit, a QR code was generated for that user's Aura account.
In other words, since we might see another user's QR code, we might also see the student's full name, the status of the COVID-19 test result, and the date the student was certified or denied.
ProWellTech hasn't enumerated every QR code, but through limited testing it found that the bug may have exposed around 15,000 QR codes.
We described the app's vulnerabilities to Will Strafach, security researcher and CEO of Guardian Firewall. Strafach said the app sounded like "urgent work" and that the enumeration bug could easily be detected during a security check. "The fact that they were unaware tells me they didn't even bother doing it," he said. And the keys left in the source code, Strafach said, suggested "a 'just-ship-it' attitude towards a worrying extreme."
An email sent by Albion President Matthew Johnson, dated August 18 and shared with ProWellTech, confirmed that the school has since initiated a security review of the app.
We sent Nucleus several questions, including vulnerabilities and whether the app had gone through a security check. Nucleus fixed the QR code vulnerability after ProWellTech detailed the bug. But a company spokesperson, Tony Defazio, did not provide comment. "I advised the company about your request," he said. The spokesperson did not return follow-up emails.
In response to the student's findings, Albion She said that the app complied with the Health Insurance Portability and Accountability Act, or HIPAA, which regulates the privacy of health data and medical records. HIPAA also believes that companies, including universities, are responsible for security gaps related to health data. This can mean heavy fines or, in some cases, prosecution.
Albion spokesman Chuck Carlson did not respond to our emails asking for comments.
At least two other schools, Bucknell University and Temple University, are reopening for the fall semester requiring students to submit two negative COVID-19 tests via Genetworx. Schools don't use Aura, but their internal student app to provide test results.
Albion's students, meanwhile, are divided on whether to comply or refuse and face the consequences. @ Q3w3e3 he said he won't use the app. "I'm trying to work with college to find an alternative way to get tested," he told ProWellTech.
Parents also expressed their anger at politics.
"I absolutely hate him. I think it's a violation of her privacy and civil liberties, "said Elizabeth Burbank, a parent of an Albion student, who signed the petition against the school's monitoring effort.
"I want to keep my daughter safe, of course, and help others too. We are more than happy to do our part. I don't think, however, that a GPS tracker is the way to go, "he said." Let's wash our hands. Eat healthy. And keep researching treatments and vaccines. That should be our goal.
"I intend to do everything possible to protect my daughter's right to privacy and challenge her right to free movement in her community," she said.
Send suggestions securely on Signal and WhatsApp at +1 646-755-8849 or send an encrypted email to: [email protected]