Featured Article

Fearing coronavirus, a Michigan college is tracking its students with a flawed app

And students have no way to opt out

Comment

Image Credits: (TechCrunch composite) / Getty Images

Schools and universities across the United States are split on whether to open for the fall semester, thanks to the ongoing pandemic.

Albion College, a small liberal arts school in Michigan, said in June it would allow its nearly 1,500 students to return to campus for the new academic year starting in August. Lectures would be limited in size and the semester would finish by Thanksgiving rather than December. The school said it would test both staff and students upon their arrival to campus and throughout the academic year.

But less than two weeks before students began arriving on campus, the school announced it would require them to download and install a contact-tracing app called Aura, which it says will help it tackle any coronavirus outbreak on campus.

There’s a catch. The app is designed to track students’ real-time locations around the clock, and there is no way to opt out.

The Aura app lets the school know when a student tests positive for COVID-19. It also comes with a contact-tracing feature that alerts students when they have come into close proximity with a person who tested positive for the virus. But the feature requires constant access to the student’s real-time location, which the college says is necessary to track the spread of any exposure.

The school’s mandatory use of the app sparked privacy concerns and prompted parents to launch a petition to make using the app optional.

Worse, the app had at least two security vulnerabilities only discovered after the app was rolled out. One of the vulnerabilities allowed access to the app’s back-end servers. The other allowed us to infer a student’s COVID-19 test results.

The vulnerabilities were fixed. But students are still expected to use the app or face suspension.

Track and trace

Exactly how Aura came to be and how Albion became its first major customer is a mystery.

Aura was developed by Nucleus Careers in the months after the pandemic began. Nucleus Careers is a Pennsylvania-based recruiting firm founded in 2020, with no apparent history or experience in building or developing healthcare apps besides a brief mention in a recent press release. The app was built in partnership with Genetworx, a Virginia-based lab providing coronavirus tests. (We asked Genetworx about the app and its involvement, but TechCrunch did not hear back from the company.)

The app helps students locate and schedule COVID-19 testing on campus. Once a student is tested for COVID-19, the results are fed into the app.

If the test comes back negative, the app displays a QR code which, when scanned, says the student is “certified” free of the virus. If the student tests positive or has yet to be tested, the student’s QR code will read “denied.”

Aura uses the student’s real-time location to determine if they have come into contact with another person with the virus. Most other contact-tracing apps use nearby Bluetooth signals, which experts say is more privacy-friendly.

Hundreds of academics have argued that collecting and storing location data is bad for privacy.

The Aura app generates a QR code based on the student’s COVID-19 test results. Scan the QR code to reveal the student’s test result status. (Image: TechCrunch)

In addition to having to install the app, students were told they are not allowed to leave campus for the duration of the semester without permission over fears that contact with the wider community might bring the virus back to campus.

If a student leaves campus without permission, the app will alert the school, and the student’s ID card will be locked and access to campus buildings will be revoked, according to an email to students, seen by TechCrunch.

Students are not allowed to turn off their location and can be suspended and “removed from campus” if they violate the policy, the email read.

Private universities in the U.S. like Albion can largely set and enforce their own rules and have been likened to “shadow criminal justice systems — without any of the protections or powers of a criminal court,” where students can face discipline and expulsion for almost any reason with little to no recourse. Last year, TechCrunch reported on a student at Tufts University who was expelled for alleged grade hacking, despite exculpatory evidence in her favor.

Albion said in an online Q&A that the “only time a student’s location data will be accessed is if they test positive or if they leave campus without following proper procedure.” But the school has not said how it will ensure that student location data is not improperly accessed, or who has access.

“I think it’s more creepy than anything and has caused me a lot of anxiety about going back,” one student going into their senior year, who asked not to be named, told TechCrunch.

A ‘rush job’

One Albion student was not convinced the app was safe or private.

The student, who asked to go by her Twitter handle @Q3w3e3, decompiles and analyzes apps on the side. “I just like knowing what apps are doing,” she told TechCrunch.

Buried in the app’s source code, she found hardcoded secret keys for the app’s backend servers, hosted on Amazon Web Services. She tweeted her findings — with careful redactions to prevent misuse — and reported the problems to Nucleus, but did not hear back.

(Source: Twitter)

A security researcher, who asked to go by her handle Gilda, was watching the tweets about Aura roll in. Gilda also dug into the app and found and tested the keys.

“The keys were practically ‘full access’,” Gilda told TechCrunch. She said the keys — since changed — gave her access to the app’s databases and cloud storage in which she found patient data, including COVID-19 test results with names, addresses and dates of birth.

Nucleus pushed out an updated version of the app on the same day with the keys removed, but did not acknowledge the vulnerability.

TechCrunch also wanted to look under the hood to see how Aura works. We used a network analysis tool, Burp Suite, to understand the network data going in and out of the app. (We’ve done this a few times before.) Using our spare iPhone, we registered an Aura account and logged in. The app normally pulls in recent COVID-19 tests. In our case, we didn’t have any and so the scannable QR code, generated by the app, declared that I had been “denied” clearance to enter campus — as to be expected.

But our network analysis tool showed that the QR code was not generated on the device but on a hidden part of Aura’s website. The web address that generated the QR code included the Aura user’s account number, which isn’t visible from the app. If we increased or decreased the account number in the web address by a single digit, it generated a QR code for that user’s Aura account.

In other words, because we could see another user’s QR code, we could also see the student’s full name, their COVID-19 test result status and what date the student was certified or denied.

TechCrunch did not enumerate each QR code, but through limited testing found that the bug may have exposed about 15,000 QR codes.

We described the app’s vulnerabilities to Will Strafach, a security researcher and chief executive at Guardian Firewall. Strafach said the app sounded like a “rush job,” and that the enumeration bug could be easily caught during a security review. “The fact that they were unaware tells me they did not even bother to do this,” he said. And, the keys left in the source code, said Strafach, suggested “a ‘just-ship-it’ attitude to a worrisome extreme.”

An email sent by Albion president Matthew Johnson, dated August 18 and shared with TechCrunch, confirmed that the school has since launched a security review of the app.

We sent Nucleus several questions — including about the vulnerabilities and if the app had gone through a security audit. Nucleus fixed the QR code vulnerability after TechCrunch detailed the bug. But a spokesperson for the company, Tony Defazio, did not provide comment. “I advised the company of your inquiry,” he said. The spokesperson did not return follow-up emails.

In response to the student’s findings, Albion said that the app was compliant with the Health Insurance Portability and Accountability Act, or HIPAA, which governs the privacy of health data and medical records. HIPAA also holds companies — including universities — accountable for security lapses involving health data. That can mean heavy fines or, in some cases, prosecution.

Albion spokesperson Chuck Carlson did not respond to our emails requesting comment.

At least two other schools, Bucknell University and Temple University, are reopening for the fall semester by requiring students to present two negative COVID-19 tests through Genetworx. The schools are not using the Aura app, but their own in-house student app to deliver the test results.

Albion students, meanwhile, are split on whether to comply, or refuse and face the consequences. @Q3w3e3 said she will not use the app. “I’m trying to work with the college to find an alternative way to be tested,” she told TechCrunch.

Parents have also expressed their anger at the policy.

“I absolutely hate it. I think it’s a violation of her privacy and civil liberties,” said Elizabeth Burbank, a parent of an Albion student, who signed the petition against the school’s tracking effort.

“I do want to keep my daughter safe, of course, and help keep others safe as well. We are more than happy to do our part. I do not believe however, a GPS tracker is the way to go,” she said. “Wash our hands. Eat healthy. And keep researching treatments and vaccines. That should be our focus.

“I do intend to do all I can to protect my daughter’s right to privacy and challenge her right to free movement in her community,” she said.


Send tips securely over Signal and WhatsApp to +1 646-755-8849 or send an encrypted email to: zack.whittaker@protonmail.com

More TechCrunch

When you look at how generative AI is being implemented across developer tools, the focus for the most part has been on generating code, as with Github Copilot. Greptile, an…

Greptile raises $4M to build an AI-fueled code base expert

The models tended to answer questions inconsistently, which reflects biases embedded in the data used to train the models.

Study finds that AI models hold opposing views on controversial topics

A growing number of businesses are embracing data models — abstract models that organize elements of data and standardize how they relate to one another. But as the data analytics…

Cube is building a ‘semantic layer’ for company data

Stock-trading platform Robinhood is diving deeper into the cryptocurrency realm with the acquisition of crytpo exchange Bitstamp. Robinhood said it expects the deal to close in the first half of 2025, with…

Robinhood acquires global crypto exchange Bitstamp for $200M

Torpago’s Powered By product is geared for regional and community banks, with under $20 billion in assets, to launch their own branded cards and spend management programs.

Fintech Torpago has a unique way to compete with Brex and Ramp: turning banks into customers

Over half of Americans wear corrective glasses or contact lenses. While there isn’t a shortage of low-cost and luxury frames available online or in stores, consumers can only buy them…

Eyebot raised $6M for AI-powered kiosks that provide 90-second eye exams without optometrist

Google on Thursday said it is rolling out NotebookLM, its AI-powered note-taking assistant, to over 200 new countries, nearly six months after opening its access in the U.S. The platform,…

Google’s updated AI-powered NotebookLM expands to India, UK and over 200 other countries

Inflation and currency devaluation have always been a growing concern for Africans with bank accounts.

Starting in war-torn Sudan, YC-backed Elevate now provides fintech to freelancers globally

Featured Article

Amazon buys Indian video streaming service MX Player

Amazon has agreed to acquire key assets of Indian video streaming service MX Player from the local media powerhouse Times Internet, the latest step by the e-commerce giant to make its services and brand popular in smaller cities and towns in the key overseas market.  The two firms reached a…

5 hours ago
Amazon buys Indian video streaming service MX Player

Dealt is now building a service platform for retailers instead of end customers.

Dealt turns retailers into service providers and proves that pivots sometimes work

Snowflake is the latest company in a string of high-profile security incidents and sizable data breaches caused by the lack of MFA.

Hundreds of Snowflake customer passwords found online are linked to info-stealing malware

The buy will benefit ChromeOS, Google’s lightweight Linux-based operating system, by giving ChromeOS users greater access to Windows apps “without the hassle of complex installations or updates.”

Google acquires Cameyo to bring Windows apps to ChromeOS

Mistral is no doubt looking to grow revenue as it faces considerable — and growing — competition in the generative AI space.

Mistral launches new services and SDK to let customers fine-tune its models

The warning for the Ai Pin was issued “out of an abundance of caution,” according to Humane.

Humane urges customers to stop using charging case, citing battery fire concerns

The keynote will be focused on Apple’s software offerings and the developers that power them, including the latest versions of iOS, iPadOS, macOS, tvOS, visionOS and watchOS.

Watch Apple kick off WWDC 2024 right here

As WWDC 2024 nears, all sorts of rumors and leaks have emerged about what iOS 18 and its AI-powered apps and features have in store.

What to expect from Apple’s AI-powered iOS 18 at WWDC 2024

Welcome to Elon Musk’s X. The social network formerly known as Twitter where the rules are made up and the check marks don’t matter. Or do they? The Tesla and…

Elon Musk’s X: A complete timeline of what Twitter has become

TechCrunch has kept readers informed regarding Fearless Fund’s courtroom battle to provide business grants to Black women. Today, we are happy to announce that Fearless Fund CEO and co-founder Arian…

Fearless Fund’s Arian Simone coming to Disrupt 2024

Bridgy Fed is one of the efforts aimed at connecting the fediverse with the web, Bluesky and, perhaps later, other networks like Nostr.

Bluesky and Mastodon users can now talk to each other with Bridgy Fed

Zoox, Amazon’s self-driving unit, is bringing its autonomous vehicles to more cities.  The self-driving technology company announced Wednesday plans to begin testing in Austin and Miami this summer. The two…

Zoox to test self-driving cars in Austin and Miami 

Called Stable Audio Open, the generative model takes a text description and outputs a recording up to 47 seconds in length.

Stability AI releases a sound generator

It’s not just instant-delivery startups that are struggling. Oda, the Norway-based online supermarket delivery startup, has confirmed layoffs of 150 jobs as it drastically scales back its expansion ambitions to…

SoftBank-backed grocery startup Oda lays off 150, resets focus on Norway and Sweden

Newsletter platform Substack is introducing the ability for writers to send videos to their subscribers via Chat, its private community feature, the company announced on Wednesday. The rollout of video…

Substack brings video to its Chat feature

Hiya, folks, and welcome to TechCrunch’s inaugural AI newsletter. It’s truly a thrill to type those words — this one’s been long in the making, and we’re excited to finally…

This Week in AI: Ex-OpenAI staff call for safety and transparency

Ms. Rachel isn’t a household name, but if you spend a lot of time with toddlers, she might as well be a rockstar. She’s like Steve from Blues Clues for…

Cameo fumbles on Ms. Rachel fundraiser as fans receive credits instead of videos  

Cartwheel helps animators go from zero to basic movement, so creating a scene or character with elementary motions like taking a step, swatting a fly or sitting down is easier.

Cartwheel generates 3D animations from scratch to power up creators

The new tool, which is set to arrive in Wix’s app builder tool this week, guides users through a chatbot-like interface to understand the goals, intent and aesthetic of their…

Wix’s new tool taps AI to generate smartphone apps

ClickUp Knowledge Management combines a new wiki-like editor and with a new AI system that can also bring in data from Google Drive, Dropbox, Confluence, Figma and other sources.

ClickUp wants to take on Notion and Confluence with its new AI-based Knowledge Base

New York City, home to over 60,000 gig delivery workers, has been cracking down on cheap, uncertified e-bikes that have resulted in battery fires across the city.  Some e-bike providers…

Whizz wants to own the delivery e-bike subscription space, starting with NYC

This is the last major step before Starliner can be certified as an operational crew system, and the first Starliner mission is expected to launch in 2025. 

Boeing’s Starliner astronaut capsule is en route to the ISS