Despite the flashy ads, however, it’s still too early to tell how well Israel’s program will work in practice—or what that will mean for vaccine passports in general. Some ethicists argue that such programs may further entrench existing inequalities, and this is already happening with Israel’s pass, since few Palestinians in the occupied territories of Gaza and the West Bank have access to vaccines.
The green pass is also a potential privacy nightmare, says Orr Dunkelman, a computer science professor at Haifa University and a board member of Privacy Israel. He says the pass reveals information that those checking credentials don’t need to know, such as the date a user recovered from covid or got a vaccine. The app also uses an outdated encryption library that is more vulnerable to security breaches, Orr says. Crucially, because the app is not open source, no third-party experts can vet whether these concerns are founded.
“This is a catastrophe in the making,” says Ran Bar Zik, a software columnist for the newspaper Haaretz.
Zik recommends another option currently available under the green pass program: downloading a paper vaccination certificate instead of using the app. Although that’s possible, the app is expected to become the most widespread verification method.
In the US, developers are trying to address such privacy concerns ahead of any major rollout. Ramesh Raskar runs the PathCheck Foundation at MIT, which has partnered with the design consultancy Ideo on a low-tech solution. Their prototype uses a paper card, similar to the one people currently receive when they’re vaccinated.
The paper card could offer multiple forms of verification, scannable in the form of QR codes, allowing you to show a concert gatekeeper only your vaccination status while displaying another, more information-heavy option to health-care providers.
“Getting on a bus, or getting into a concert, you need to have a solution that is very easy to use and that provides a level of privacy protection,” he says. But other situations may require more information: an airline wants to know that you are who you say you are, for example, and hospitals need accurate medical records.
It’s not just about making sure you don’t have to hand over personal information to get into a bar, though: privacy is also important for those who are undocumented or who mistrust the government, Raskar says. It’s important for companies not to create another “hackable repository” when they view your information, he adds.