Major vulnerability shows dangers of mandatory contact-tracing apps

An app in Qatar demanded access to user data and potentially exposed users to being tracked by third parties.
 By 
Jack Morse
 on 
Major vulnerability shows dangers of mandatory contact-tracing apps
Definitely a bug, not a feature. Credit: vicky leta / mashable

Meant to keep the residents of Qatar coronavirus free, a new mandatory contact-tracing app instead put their privacy at risk.

The government of Qatar, like many around the world and in the U.S., is pushing contact-tracing apps as a tool in the battle against the spread of the coronavirus. Unfortunately, the Qatar Ministry Of Interior's mandatory EHTERAZ app exposed users to a wide range of potential violations.

So found Amnesty International, which on Tuesday reported that a vulnerability in the app "would have allowed cyber attackers to access highly sensitive personal information, including the name, national ID, health status and location data of more than one million users."


You May Also Like

At the heart of the matter was a QR code associated with the app. Each app user received a unique QR code that contained info like whether or not they had the coronavirus, where they were being quarantined, and their name. All anyone needed to access the QR code was a national ID number, which, you guessed it, Amnesty International notes "follow a consistent format" and are easily guessed.

Thankfully, Amnesty International writes the app was patched after the organization alerted authorities, but the mandatory nature of the app along with its excessive permissions created the opportunity for a perfect privacy-crushing storm.

Mashable Image
The EHTERAZ app. Credit: screenshot / google play

"This incident should act as a warning to governments around the world rushing out contact tracing apps that are too often poorly designed and lack privacy safeguards," Claudio Guarnieri, the head of Amnesty International's Security lab, explained in a statement. "If technology is to play an effective role in tackling the virus, people need to have confidence that contact tracing apps will protect their privacy and other human rights."

Indeed, even putting aside the security vulnerability, EHTERAZ demands a shocking amount of access to function. According to the Google Play store's permission page for the app, EHTERAZ not only tracks users' locations, but can "modify or delete the contents of your USB storage" and "disable your screen lock" (among other things).

Mashable Image
Well, that's quite a lot. Credit: screenshot / google play

An app with this much access, which potentially leaks users data, is a hacker's dream target — and potentially a tool for oppressive regimes.

As officials around the world continue to push for contact-tracing apps, it's worth remembering that the limited examples we have seen in the real world have been anything but inspiring. Essentially, many contact-tracing apps don't work and violate users' privacy at the same time.

SEE ALSO: Contact-tracing app caught sharing location data with Foursquare

That the people of Qatar were instructed to download an app riddled with security vulnerabilities doesn't exactly suggest the situation is about to change.

Mashable Image
Jack Morse

Professionally paranoid. Covering privacy, security, and all things cryptocurrency and blockchain from San Francisco.

Mashable Potato

Recommended For You
Roblox rolls out mandatory age checks for all users
Several smartphone screens showing the steps to verify a user's age on Roblox.


Hackers are exploiting a vulnerability in lots of e-commerce sites
Fish-eye lens view of a computer screen with hacking stuff on it

How to contact Amazon customer service during your Big Spring Sale shopping spree
illustration of brown packages

New Tinder users in the UK will now need to scan their faces
Tinder on app store appearing on iPhone

Trending on Mashable
NYT Connections hints today: Clues, answers for April 3, 2026
Connections game on a smartphone

Wordle today: Answer, hints for April 3, 2026
Wordle game on a smartphone


NYT Strands hints, answers for April 3, 2026
A game being played on a smartphone.

You can track Artemis II in real time as Orion flies to the moon
Victor Glover and Reid Wiseman piloting the Orion spacecraft
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!