{"id":19136,"date":"2021-04-09T16:50:34","date_gmt":"2021-04-09T16:50:34","guid":{"rendered":"https:\/\/davidgerard.co.uk\/blockchain\/?p=19136"},"modified":"2021-12-20T19:37:53","modified_gmt":"2021-12-20T19:37:53","slug":"new-yorks-excelsior-pass-for-covid-19-on-ibm-blockchain-doing-the-wrong-thing-badly","status":"publish","type":"post","link":"https:\/\/davidgerard.co.uk\/blockchain\/2021\/04\/09\/new-yorks-excelsior-pass-for-covid-19-on-ibm-blockchain-doing-the-wrong-thing-badly\/","title":{"rendered":"New York&#8217;s Excelsior Pass for COVID-19, on IBM Blockchain: doing the wrong thing, badly"},"content":{"rendered":"<p>The New York &#8220;Excelsior Pass&#8221; is a COVID-19 vaccine passport system. It proudly proclaims its use of &#8220;secure technologies, like blockchain and encryption.&#8221; [<a href=\"https:\/\/www.governor.ny.gov\/news\/governor-cuomo-announces-launch-excelsior-pass-help-fast-track-reopening-businesses-and\"><i>press release<\/i><\/a>]<\/p>\n<p>The Excelsior Pass is a deployment of IBM Digital Health Pass, a project of the IBM Watson Works vaporware project \u2014 now that the IBM Blockchain vaporware project <a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2021\/03\/05\/news-india-crypto-ban-north-korea-bitmex-execs-to-appear-ibm-blockchain-dead-more-mcafee-charges\/\">has shut down as a separate unit,<\/a> and been folded into Watson. [<a href=\"https:\/\/www.ibm.com\/products\/digital-health-pass\"><i>IBM<\/i><\/a>]<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2021\/04\/09\/new-yorks-excelsior-pass-for-covid-19-on-ibm-blockchain-doing-the-wrong-thing-badly\/excelsior-pass\/\" rel=\"attachment wp-att-19138\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-19138\" src=\"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2021\/04\/excelsior-pass.jpg\" alt=\"\" width=\"510\" height=\"315\" srcset=\"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2021\/04\/excelsior-pass.jpg 680w, https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2021\/04\/excelsior-pass-300x185.jpg 300w, https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2021\/04\/excelsior-pass-348x215.jpg 348w\" sizes=\"auto, (max-width: 510px) 100vw, 510px\" \/><\/a><\/p>\n<p style=\"text-align: center;\"><small><i>An official promotional image for Excelsior Pass: a stock photo, with mockup screenshots pastede on yay.<\/i> [<i><a href=\"https:\/\/web.archive.org\/web\/20210409155820if_\/https:\/\/epass.ny.gov\/home\">EPass<\/a><\/i>]<\/small><\/p>\n<p>&nbsp;<\/p>\n<p>Tim Paydos, global general manager of government for IBM, spoke to GovTech, and was remarkably unclear on where the data is kept: [<a href=\"https:\/\/www.govtech.com\/health\/How-Excelsior-Pass-the-First-US-Vaccine-Passport-Works.html\"><i>GovTech<\/i><\/a>]<\/p>\n<blockquote><p>IBM purposefully didn\u2019t build a centralized database for Excelsior Pass in order to avoid creating a giant target for hackers.<\/p>\n<p>\u201cAll of the data stays distributed,\u201d Paydos said. \u201cWe\u2019re not creating a big intergalactic database in the sky. We wouldn\u2019t want to do that, nor given the time urgency could we do that.\u201d<\/p><\/blockquote>\n<p>This claim is factually incorrect, if the following is true:<\/p>\n<blockquote><p>The app was actually based on work IBM did with Maersk on shipping containers moving across the world, and Paydos said it should work for travelers moving between nations as well.<\/p><\/blockquote>\n<p>This means that IBM reworked the TradeLens system for the Digital Health Pass.<\/p>\n<p>TradeLens was used for the Maersk supply chain blockchain project \u2014 one of the two systems the IBM Blockchain unit ever sold. (The other being the WalMart supply chain project, which apparently wasn&#8217;t TradeLens.)<\/p>\n<p>TradeLens operated as a completely normal centralised system \u2014 administered by the company, with all servers living on the IBM Cloud. The &#8220;blockchain&#8221; bit is that the back end data store is Hyperledger.<\/p>\n<p>TradeLens didn&#8217;t do so well \u2014 it turns out that nobody in business wants their competitors all up in their deals. [<a href=\"https:\/\/www.supplychainmovement.com\/future-blockchain-based-trade-platform-tradelens-looks-uncertain\/\"><i>Supply Chain Movement<\/i><\/a><i>, 2019<\/i>] Even Maersk&#8217;s vendors couldn&#8217;t really see the point of TradeLens on a blockchain, and only signed up because Maersk, as central authority, required them to. &#8220;I believe the industry is quietly and politely saying they are not interested or at least not currently interested,&#8221; said one vendor; &#8220;Blockchain is the overly persistent salesperson.&#8221; [<a href=\"https:\/\/www.joc.com\/technology\/skepticism-maersk-ibm%E2%80%99s-tradelens-hit-bigger-blockchain-questions_20180813.html\"><i>Journal of Commerce<\/i><\/a><i>, 2018, <\/i><a href=\"https:\/\/archive.is\/YToEF\"><i>archive<\/i><\/a>]<\/p>\n<p>If Digital Health Pass is based on TradeLens, then it would work similarly \u2014 and, functionally, it&#8217;ll be a completely centrally administered system.<\/p>\n<p>Which is, of course, precisely what you want from a government function \u2014 &#8220;blockchain&#8221; will only mean &#8220;slow distributed database.&#8221; You&#8217;d have to be high on blockchain fumes to do it any other way than fully centralised.<\/p>\n<p>The Hyperledger bit might make redacting erroneous data unduly difficult, which is what they&#8217;d get for <a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2018\/06\/28\/ibm-the-gdpr-and-blockchain-whatever-that-word-specifically-means\/\">putting incredibly sensitive personal data into a Merkle tree.<\/a><\/p>\n<p>The ethics and medical validity of vaccine passports have been widely questioned \u2014 particularly when vaccines are in short supply, and there&#8217;s a black market on the darknet for fake vaccine documentation. [<a href=\"https:\/\/www.eff.org\/deeplinks\/2020\/12\/vaccine-passports-stamp-inequity\"><i>EFF<\/i><\/a><i>; <\/i><a href=\"https:\/\/www.bbc.co.uk\/news\/technology-56489574\"><i>BBC<\/i><\/a>]<\/p>\n<p>More specifically, the Excelsior Pass app asks for data on vaccination, but also on antigen tests [<a href=\"https:\/\/covid19vaccine.health.ny.gov\/excelsior-pass-frequently-asked-questions\"><i>NY Health<\/i><\/a>] \u2014 which are much better than nothing, but have substantial rates of false negatives. And the Excelsior Pass system is slow to update and clunky to use \u2014 you have to show ID at the same time to use it. [<a href=\"https:\/\/www.washingtonpost.com\/technology\/2021\/04\/08\/vaccine-passport-new-york-excelsior-pass\/\"><i>Washington Post<\/i><\/a><i>; <\/i><a href=\"https:\/\/www.reddit.com\/r\/nycCoronavirus\/comments\/mj0yd3\/excelsior_pass_not_found_in_system\/\"><i>Reddit<\/i><\/a>]<\/p>\n<p>I was also particularly impressed to see that NY, not being a health care provider, explicitly disclaims protection of this extremely sensitive medical data under HIPAA rules. But they absolutely won&#8217;t use your data for purposes other than the public health! Unless they do. [<a href=\"http:\/\/epass.ny.gov\/terms\"><i>NY EPass<\/i><\/a><i>, <\/i><a href=\"https:\/\/web.archive.org\/web\/20210326222133if_\/http:\/\/epass.ny.gov\/terms\"><i>archive<\/i><\/a>]<\/p>\n<p>So what New York has paid IBM to do is to use a superfluous technology to implement a questionable idea, badly. So far, so blockchain.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/davidgerard.co.uk\/blockchain\/2020\/03\/13\/number-go-down-corona-chan-loves-bitcoin\/coronachan-header\/\" rel=\"attachment wp-att-17485\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-17485\" src=\"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2020\/03\/coronachan-header.jpg\" alt=\"\" width=\"510\" height=\"315\" srcset=\"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2020\/03\/coronachan-header.jpg 680w, https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2020\/03\/coronachan-header-300x185.jpg 300w, https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2020\/03\/coronachan-header-348x215.jpg 348w\" sizes=\"auto, (max-width: 510px) 100vw, 510px\" \/><\/a><\/p>\n<p style=\"text-align: center;\"><small><i>Corona-chan looks forward to seeing you out and about!<\/i><\/small><\/p>\n<br><br><div align=\"center\"><p><a href=\"https:\/\/www.patreon.com\/bePatron?u=8420236\"><img src=\"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2021\/10\/become_a_patron_button.svg\" alt=\"Become a Patron!\" title=\"Become a Patron!\" width=217 height=51><\/a><br><p style=\"align:center;\" class=\"patreon-badge\"><i>Your subscriptions keep this site going. <a href=\"https:\/\/www.patreon.com\/bePatron?u=8420236\">Sign up today!<\/a><\/i><\/p><\/div>","protected":false},"excerpt":{"rendered":"<p>Corona-chan looks forward to seeing you out and about!<\/p>\n","protected":false},"author":1,"featured_media":17485,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[74,2211,2210,64,316,127,830,594,831],"class_list":["post-19136","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorised","tag-blockchain","tag-digital-health-pass","tag-excelsior-pass","tag-hyperledger","tag-ibm","tag-ibm-watson","tag-maersk","tag-new-york","tag-tradelens"],"jetpack_featured_media_url":"https:\/\/davidgerard.co.uk\/blockchain\/wp-content\/uploads\/2020\/03\/coronachan-header.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/posts\/19136","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/comments?post=19136"}],"version-history":[{"count":28,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/posts\/19136\/revisions"}],"predecessor-version":[{"id":19165,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/posts\/19136\/revisions\/19165"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/media\/17485"}],"wp:attachment":[{"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/media?parent=19136"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/categories?post=19136"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/davidgerard.co.uk\/blockchain\/wp-json\/wp\/v2\/tags?post=19136"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}