Assay summary

For features, implementation choices, applied methodology and other details, see navigation above and the sidebar to the right.

How effective is the App against COVID-19?

The App is similarly effective to other Apps implementing Contact Tracing.

What are the downsides, or risks of using this App?

The App has several privacy issues which can be avoided through a changed implementation including:

  • The App Operator can silently upload any App User’s complete contact history and supposedly secret Base ID. This given the App Operator the ability to silently assemble a real-time social graph of all App Users. This is unnecessary for the stated purpose of the App and not conveyed to App User.

  • The App Operator can easily determine the real-world identity of any App User who has entered their phone number into the App.

  • Many aspects of the technology, operations and governance of the App are not documented, nor independently overseen. Where information exists, App Users largely depend on the word of the App Creators only.

Recommendations to App Users

Before you download Bluezone, carefully consider the risks identified in this assay. Depending on your personal situation, you may decide that the risks of running the August 2020 Bluezone version, or any earlier version, may outweigh the potential benefits. For more details, please read the details of this assay.

Disclaimer and other notes on the assay

  • Please note the general disclaimer. We appreciate feedback and corrections.

  • This assay is not exhaustive, for reasons that include available resources and the unavailability of key documentation about the App.

  • This assay relies on English-language documents, which may be less complete and less accurate than any presumed Vietnamese-language documents. Vietnamese-language documents were accessed with Google Translate, which may produce inaccurate results. Also, many of the available English-language documents were clearly written by non-native English speakers and often use terms that native English speakers would not use, or not use in this context. Our interpretation of some of those terms may be incorrect with respect to the intention of the writer.