Flaw in Philippines’ contact-tracing app served up data on 30K health care providers, research finds

The flaw has been fixed, but it’s a reminder of how software tools used to combat the pandemic can open up new fronts in data insecurity
contact tracing, coronavirus
(Getty Images)

A web and mobile phone application that the Philippines government uses to track coronavirus cases contained a flaw that could have allowed access to the names of tens of thousands of health care providers that use the app in that country, according to new research.

The flaw has been fixed, but it stands out as another cautionary tale of how software tools used to combat the pandemic can open up new fronts in data insecurity.

Multinational company Dure Technologies and officials from the World Health Organization and the Philippines Department of Health developed the app to efficiently report COVID-19 cases and help with contact tracing, and released it in June. But when researchers from the University of Toronto’s Citizen Lab investigated the app’s code, they found pressing security issues.

A web version of the app, which is known as COVID-KAYA, had a flaw in its authentication logic that revealed the names of over 30,000 health care providers signed up for the software, the researchers said. The Android version of the app was buggy, too: It allowed outsiders to access its internal programming interface, the inner hub of the software. The researchers confirmed in late October that Dure Technologies fixed the flaws.


But the bigger issue is the potential foothold that the app could have provided an attacker.

“We are concerned but did not confirm that an attacker could also leverage this vulnerability to cause the app to reveal sensitive patient data,” Citizen Lab researchers Pellaeon Lin, Jeffrey Knockel, Adam Senft, Irene Poetranto, Stephanie Tran and Ron Deibert wrote in a blog post.

The Philippines has reported some 7,700 deaths from COVID-19 and 401,000 coronavirus cases, according to Johns Hopkins University data. Infections from the virus have gradually climbed for months in the Southeast Asian country.

Months into the pandemic, contact tracing apps are a staple of digital life around the world. And like any software, researchers are continuing to find bugs in them that might create bigger surveillance issues. An Amnesty International study released in June found privacy concerns in 11 such apps introduced in places as far-flung as Iceland and Bahrain.

“Even under normal circumstances, the app ecosystem is often highly insecure as a result of the collection and storage of personal data,” the Citizen Lab researchers wrote. “Given the urgency and rapid pace of development around COVID applications, these privacy and security issues are likely to be magnified.”


Dure Technologies did not respond to a request for comment Wednesday on Citizen Lab’s findings.

Sean Lyngaas

Written by Sean Lyngaas

Sean Lyngaas is CyberScoop’s Senior Reporter covering the Department of Homeland Security and Congress. He was previously a freelance journalist in West Africa, where he covered everything from a presidential election in Ghana to military mutinies in Ivory Coast for The New York Times. Lyngaas’ reporting also has appeared in The Washington Post, The Economist and the BBC, among other outlets. His investigation of cybersecurity issues in the nuclear sector, backed by a grant from the Pulitzer Center on Crisis Reporting, won plaudits from industrial security experts. He was previously a reporter with Federal Computer Week and, before that, with Smart Grid Today. Sean earned a B.A. in public policy from Duke University and an M.A. in International Relations from The Fletcher School of Law and Diplomacy at Tufts University.

Latest Podcasts