Site navigation

Scot-Secure 2023 | Security Through Anonymisation

Michael Edgar

,

anonymisation
At the final session of DIGIT’s Scot-Secure 2023 summit, Leo Cunningham and Kajus Šeštokas of Flo discussed their app’s urgent transformation in response to a rapid political shift.

Having dealt with transforming their service amid major social changes, their presentation told the story of the challenges and risks they took to deliver the anonymous mode to their menstrual tracking app – a new feature designed to keep its clients safe from the threat of privacy breaches following a major reproductive rights case law being struck down.

The talk underscored how central tech is to its user’s lives — and just how swiftly companies must act to keep its users safe from external consequences.

The Back Drop

In June of 2022, the United States Supreme Court overturned a case law known as Roe v. Wade, which established the legal right to an abortion across the US. The overturn enabled individual states to regulate reproductive care, in some cases banning abortions for patients who were over six weeks pregnant.

In the weeks following the Roe v. Wade reversal, there was a growing fear that government bodies and private corporations would be able to access the data stored within the menstrual tracking apps in order to establish if a person had been pregnant and potentially had an abortion. 

Menstrual tracking app Flo was at risk not just to lose customers, but to lose consumer trust if it could no longer safely provide autonomy to its users. 

The race to develop a functional anonymous mode was on as multiple hacking groups announced they would try and breach reproductive health data from multiple menstrual tracking apps. 

“We live in some sort of Handmaid’s Tale episode,” Leo Cunningham, chief information security officer at Flo commented while speaking at Scot-Secure. 

At the time, most of Flo’s engineering team was located in Belarus, which borders both Ukraine and Russia. They were at risk during the early months of Russia’s invasion due to Belarus being in close proximity to Ukraine’s capital city Kyiv, and had to be relocated to the UK.

With 256 million users on the app, 50 million of which were monthly users, it needed to develop a way to keep data secure in a worst case scenario. 

Out of this divisive political climate, Flo developed anonymous mode, a new feature which decouples health data from personal information, containing no unique user identifiers.

To do this, Flo partnered with Cloudflare to implement an Oblivious HTTP (OHTTP) standard. 

Oblivious HTTP

Flo understood the urgency of the situation, working with Cloudflare to launch its anonymous mode in less than four months.

The pair used an emerging standard known as OHTTP which introduced two new entities to process the HTTP requests. Cloudflare operated a relay, and Flo operated a gateway. 

Under this protocol, application requests are end-to-end encrypted between the client and the gateway, meaning the relay sees the user IP address and other requested metadata but not the application data, and the gateway sees the application data and not the user IP address. 

To do this, Flo’s client requests are first binary coded and encapsulated using a one-time-use ephemeral key. The encapsulated request is sent to the Cloudflare relay and the data is forwarded to the Flo gateway. The gateway then uses the private key with the ephemeral key to decapsulate each request, effectively burying any unique identifiers the user would have attached to them. 

“The challenge was to understand technology, what helped me was to make the connection between the purpose of the OHTTP rewrite. What’s Cloudflare’s role in that? And why would we use binary HTTP?” said Kajus Šeštokas, engineer at Flo. “Once we had some idea how we were going to build this, the developers started doing initial versions of the app, and this is where it got interesting, because we had to avoid certain types of pitfalls.”

Overcoming Obstacles

While developing anonymous mode, the engineering team found that it would be possible to intercept API traffic between mobile clients and the service’s backend. Šeštokas realised that not all requests were going through the relay.

“This is bad, because that’s what we wanted to avoid in the first place. We don’t want to know the IP address of the user, but the whole essence of the anonymous mode is that we decouple what is being sent and who sends the data,” said Šeštokas. “So if you think about all the security engineers, do they intercept traffic between the clients and the back end? Well, not really, but sometimes, yes,” he continued. 

“We needed to get back to the basics to get things right at the start.”

Flo also realised that once the data was going live on user devices, there needed to be increased security on the cloud of the client’s device.

Security measures such as an access code to enter the app would overcome this, but as Šeštokas points out, Flo also needed to look at where that information was stored, for example on an iOS keychain, which prompted Flo to focus on improving the client functionality as well. 

Testing and Integration

Another issue Flo was facing was doing efficient testing under a tight deadline. The impending risk of data breaches had to be balanced against the risk of releasing a product that had bugs in the code. Although there were never any recorded security breaches which leaked user information from menstrual tracking apps, the fear was prevalent in the users at the time. 

Once internal testing was done, they needed to have third-party vendors look at the new feature. In order to meet the tight deadline, for Šeštokas, real-time collaboration was key. He jumped on a call with the vendors to discuss the issues, rather than through painstakingly back-and-forth emails.

“I would say a collaborative approach and real-time communication really worked well under time pressure, and that’s probably one of the business’ best lessons from that,” he said.

After testing and the release of the feature, the service received good publicity as the controversial Roe v. Wade challenged reproductive autonomy and privacy, which Flo tried to offer back.

However, after publishing the feature, an onslaught of new challenges would arrive in possible insecurities of the design. 

“Slowly but surely you realise that this is the real deal, it’s not something that we mocked up,” said Šeštokas. “How do we make sure we maintain the security level that we agreed to?” 


Recommended


To maintain the security level, Flo focused its efforts into opening its code in a private bug bounty program, where researchers would try to find discrepancies in its product and sell what they found to Flo. 

Refocused

Flo subverted the model of security typically held against malicious actors, despite having no way of identifying malicious IP addresses due to their encryption. Instead, the company was forced to reexamine the IP firewall system, refocus on examining the request itself, and secure their product against it without blocking the user. 

The audience at Scot-Secure showed their admiration for the Flo engineers who worked a new offering into their service under immense pressure. The driving factor of which was to protect reproductive rights in the midst of an attack on it.

“Anonymous [Mode] is important, especially in the world that we live in,” said Cunningham. “Particularly with female data, it is imperative that we respond as a company and protect the users,” he said. 

“It is non-negotiable for us as a company.”

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data