In this document, we analyse the potential harms a large-scale deployment of the Luca system might cause to individuals, venues, and communities. The Luca system is a digital presence tracing system designed to provide health departments with the contact information necessary to alert individuals who have visited a location at the same time as a SARS-CoV-2-positive person. Multiple regional health departments in Germany have announced their plans to deploy the Luca system for the purpose of presence tracing. The system's developers suggest its use across various types of venues: from bars and restaurants to public and private events, such religious or political gatherings, weddings, and birthday parties. Recently, an extension to include schools and other educational facilities was discussed in public. Our analysis of the potential harms of the system is based on the publicly available Luca Security Concept which describes the system's security architecture and its planned protection mechanisms. The Security Concept furthermore provides a set of claims about the system's security and privacy properties. Besides an analysis of harms, our analysis includes a validation of these claims.
翻译:在这份文件中,我们分析了大规模部署卢卡系统可能对个人、地点和社区造成的潜在损害;卢卡系统是一个数字存在追踪系统,旨在向卫生部门提供必要的联系信息,以提醒那些在与SARS-CoV-2积极分子同时访问过某个地点的个人;德国多个地区卫生部门已宣布计划部署卢卡系统,以便进行现场追踪;该系统的开发商建议它在各种地点使用:从酒吧和餐馆到公共和私人活动,例如宗教或政治集会、婚礼和生日派对。最近,在公众中讨论了扩大学校和其他教育设施的问题。我们对该系统潜在危害的分析以公开的卢卡安全概念为基础,该概念描述了该系统的安全结构及其计划的保护机制。安全概念还就该系统的安全和隐私特性提出了一套索赔要求。除了分析伤害之外,我们的分析还包括核实这些索赔要求。