corona-warn-app / cwa-documentation

Project overview, general documentation, and white papers. The CWA development ends on May 31, 2023. You still can warn other users until April 30, 2023. More information:
https://coronawarn.app/en/faq/#ramp_down
Apache License 2.0
3.28k stars 345 forks source link

Why was the DCC ticketing feature implemented in the app, although the BfDI has not finished their audit yet? #850

Closed Ein-Tim closed 2 years ago

Ein-Tim commented 2 years ago

Your Question

As announced in the blog post Corona-Warn-App simplifies certificate checks when booking tickets, since version 2.15, the app offers the so called DCC ticketing feature. This feature was implemented in version 2.15, although the BfDI had and still has not finished their audit of this feature yet.

When asked on Twitter, why this was implemented, someone working at the BfDI responded:

Das müssen Sie den Herausgeber der Software fragen

As the development team is in close contact with the stakeholders (RKI/BMG), the following questions arise and could be internally clarified and then answered here:

  1. Why was the DCC ticketing feature implemented in version 2.15, although the audit by the BfDI was not finished?
  2. Was it a request by the RKI/BMG to implement the DCC ticketing feature in version 2.15 or was this brought up by the project team (SAP/T-Systems)?
  3. Should the feature be removed from the apps again until the audit from the BfDI is finished?
GisoSchroederSAP commented 2 years ago

@All, we are working on a statement about the approach to planning and implementing features in the app. Please keep in mind that our objective is to stay as up-to-date as possible with the app. However, development (including testing) will always lag behind the current decision-making process. So, yes, we are aware that the released version may not always reflect national and/or regional rulings or dynamically changing decisions and recommendations of the authorities. Obviously, we will not and cannot implement and publish anything that has not been approved by the stakeholders and the necessary legislative authorities (including BfDI).However, in the interest of time, we try to parallelize some activities within the SCRUM approach. In rare cases, this may also lead to redundant coding, but in terms of risk assessment, we accept this risk to be able to ensure timely delivery.

Be assured, we will use the momentum and we are on track to cover the ongoing legislative amendments with the next versions of the app.

Please remain patient.

Ein-Tim commented 2 years ago

@GisoSchroederSAP Thank you for letting us know that you are working on a statement! Enjoy Friday & your weekend!

Ein-Tim commented 2 years ago

Closing as the DCC ticketing feature was put on ice: https://github.com/corona-warn-app/cwa-website/issues/2218#issuecomment-1094809124.