Greg's bite: Location iNsecure, a Rotten Apple can't be trusted
TweetFollow Us on Twitter

Greg's bite: Location iNsecure, a Rotten Apple can't be trusted

By Greg Mills

Steve Jobs is the new evil Big Brother. I would like to retract my statement posted November 21, 2010: "Jobs and Apple gone evil? Not so." Remember the iconic Apple commercial of the woman running down the aisle and throwing a hammer at the theater screen picture of big brother (as in the Orwellian novel "1984")?   The evil dictator's image was shattered and we all cheered. Could Steve Job's face become the modern big brother image? This sort of location tracking that came to light last week, previously reserved for the most dangerous criminals has been applied to us all by Apple, and for what? So that Apple could sell stinking pizzas!?

As news of the audaciousness of Apple secretly tracking and recording the detailed movements of everyone who innocently purchased the hugely popular iPhone and iPad sinks in, the question of why Apple did it comes to mind.  While some still want to give Apple the benefit of the doubt, the evidence is overwhelming that the invasion of our privacy was intentional. Apple's engineers are way too methodical to have "accidentally" stored and upload detailed location data compiled on every user of the iOS, for at least a year and likely longer.

Compared to the tenuous relationship Microsoft has with its PC consumers, Apple has historically had a virtual love affair with its faithful. That legendary trust, has been built for years among long term Mac users, who have stood faithfully by their Apple computers when faced with all manor of platform marginalization from the Windows PC world. Thus, this serious betray of our trust is particularly hard to take. Labeled an "odd man out" for years for insisting on using a Mac instead of a PC, I have previously been faced with having to provide my own computer at work, since the company I was with at the time, "didn't support the Mac platform."  Ironically, the art department was able to demand and get a Mac, but as Product Marketing Manager I was forced to use my personal MacBook at work.  

As Apple has grown over the last few years, a sort of corporate mindset corruption has apparently occurred: The fanatical Apple user experience be damned, there is money to be made! Keep in mind, the change was slow and came in incremental stages, but the cynical motives at 1 Infinity Loop can no longer be denied. A fundamental change in corporate philosophy has taken place at Apple.  

Remember the frog placed in cool water on a stove will sit and be cooked to death as the water temperature slowly rises. Dropping that same frog into hot water would have gotten an immediate violent response. It feels like very hot water was just dumped on me in my relationship with Apple. Can we trust Apple to keep our data in the cloud without violating our privacy for some corporate advantage? I don't think so. Who knows how they might abuse that technology?

Apple recently has announced that it is adding a "do not track" feature to Safari to protect the privacy of web surfers; ironically, the much more invasive detailed location tracking features of iPhones and iPads was secretly still in use. I don't think anything would have changed had Apple not been caught with its pants down. I think Apple will be forced to stop tracking its consumers. A normally masterful control of the media by Apple can't control the bad spin in the press over this issue. Apple didn't come forward on its own and offer an opt out for the tracking; they were caught doing it without a meaningful choice by the consumer. I figure I have my ear to the ground on Apple issues, but I will have to admit this shocked and surprised me.

Apple certainly made the decision at the highest levels to get into the digital advertising business and to leverage the Apple platforms to accomplish that, apparently at any cost. When one looks at Google, they are doing a lot of things that make money, but the real serious money they make comes from advertising. Targeted advertising is far more lucrative and profitable than standard broad based advertising. Apple saw that, and the iAd concept was developed.  

If you run a pizza shop, for example, the notion of having an electronic full color interactive digital coupon pop up on cell phones as someone enters a local "geo-fenced" zone, is worth far more than broad un-targeted advertising programs going to hundreds of times more "unfocused consumers".  

Let's say the geo-fenced area is 1/4 of a mile each way along a major street your pizza shop is located on. If you could target potential pizza customers who are being tracked by their phones to those nearby locations, traveling along that road, during the hours between 11 am and 8 pm with a $3.99 medium pizza electronic coupon offer, that would be worth a lot of money to you. If that customer, has also been tracked over a long period of time and has a history of stopping at other pizza shops in town, that is also a value building element to location based advertising. Long term location history has tremendous value to advertising companies, apparently more than the value of customer loyalty to Apple.

The potential for adding the "electronic wallet feature" to future iPhones will leverage the targeting advertising potential even more. People who historically spend money at other pizza shops using their iPhones to pay are certainly choice customers to send electronic coupons to should they venture into your geo-fenced zone. It has been rumored that Apple plans to add an RFID chip to iPhones, that chip would support a "swipe to charge" feature to your cell phone. The iPhone would deduct the pizza charges electronically from your account and also make a note that you buy pizzas. Add that habit information to knowing where you are, and you can see where they are going with this.

It is easy to see why Apple decided to get into the electronic advertising business. The big idea is to push targeted electronic ads to the millions of consumers who also happen to own iPhones and iPads. According to recent polls, a magnitude of half of the current users of iPhones and iPads have no major objection to their locations being tracked by Apple. That however leaves half of us who are infuriated and feel seriously betrayed. I suspect the ranks of the betrayed will increase as the unexpected ramifications of insecure location data becomes better understood. I think that is why Apple didn't disclose more fully what they were doing. Some of us would vocally object if we knew. 

An invasion of privacy as a generalized notion in society rises to a fairly low level of concern. When an invasion of privacy actually happens to you with an unexpected problem resulting, the level of anger suddenly becomes much greater. The result of "location history insecurity" can be individually quite profound. Apple doesn't seem to care when the privacy of Apple individual users are weighed against the potential money they can make selling location based ads. Some years back, the calculus would have been much different. I thought Apple cared about me individually as an avid long term Mac fan. Now I am sure they really don't care about me, nearly as much as I thought they did. 

Beyond  invasion of privacy issues, the lack of meaningful notice that such detailed tracking and location recording would be the default and that a way to opt out of tracking wasn't even offered is a major issue. If half the users of iPhones were willing to submit their locations to Apple why would they track everyone regardless of they way they felt about it? As I understand it even turning off locations services didn't prevent the tracking and records generation based upon tower and Wi-Fi information. Turning off location services ought to mean you don't want to be tracked, period. 
      
As I predicted in Friday's post, a class action lawsuit will certainly be filed over this. A complaint was previously filed in San Jose California by user Jonathan Lalo seeking class action status on questionable Apple location tracking policies. Filed in December of last year, the suit was originally tailored just to take Apple to task for certain iOS apps that used location services without proper notice to consumers. I suspect that lawsuit will be modified to go after Apple for the more pervasive and general secret tracking feature on all iOS devices. See http://www.tgdaily.com/business-and-law-features/53245-apple-sued-over-data-tracking .

There is also the strong possibility that fresh federal lawsuits will be filed, specifically due to the recent secret iOS tracking revelations.  The basis of the likely class action suit is certain to be upon a combination of the violation of existing privacy laws and the lack of meaningful notice that such detailed tracking was taking place and that secret long term records were being kept. 

How can Apple claim the tracking data is "not personably identifiable" when a complete unencrypted record is found on all your personal Apple devices, which are subject to theft, hacking and loss? Give me a blank disk and five minutes access to someones Mac, I will walk away with a complete record of "location data" for every iOS device that syncs with that computer. You can also anticipate that I can figure out who the computer belongs to. So much for the notion of the location logs not being identifiable.   

Further, it wasn't ever disclosed that the computer the iOS devices sync with would also create and maintain a persistent location log going back to the very first day the iOS device was activated. While the attorneys at Apple are sure to yawn at "just another lawsuit," the implications of these suits should be meaningful to Apple.  When long time Apple faithful are so angry they are suddenly willing to sue, can Apple just shrug that off? The old Apple wouldn't want that. I am not so sure about the new Apple. 

I am of the opinion that Apple will move to create an opt in/opt out location tracking history feature common to both the Mac OS and the iOS platforms that will allow existing tracking records to be erased and no longer stored. I am convinced that while the pressure of lawsuits might be a minor factor in forcing them to amend their platforms, the real reason they will move on this issue will be the potential of lost market share. This situation is clearly going to hurt Apple sales of both devices to new users and retard sales to established upgrade customers. I certainly will not replace my aging iPhone 3Gs or iPad 1 or sign up for another year as an iOS developer until I can be darn sure Apple won't continue to abuse my trust.

Apple has been working hard to convince the enterprise and even the military that iOS devices are secure enough to trust with sensitive data. This breech of trust that merely infuriates civilians is much more of a dangerous security threat to potential enterprise and military users. Apple devices are anything but "location data secure." This is a very important defect in data security and is certain to be noticed by decision makers in business and the military.

Imagine an iPhone used by the military being captured and location files downloaded into a Mac laptop. Then the movements of that particular soldier can be graphically mapped showing troop movements in vidid detail, complete with time/date stamps. This sort of compiled location information would be an absolute gold mine to the other side.  Using detailed location data would give an enemy the exact GPS setting for missiles or bombs which would hit the barracks where the soldiers sleep. It also could potentially give away current troop concentrations by remote access to location data hacked over a cellular network.  

What business will be willing to risk the location data for its executive employees falling into the hands of competitors? What unanticipated consequences will befall users of iOS devices, simply due to trusting Apple to do no harm to them?  

I recently did a Faux art job for a customer who personally knew someone who had been fired due to location data stored on a company cell phone. It seems this salesman was spending time "on the clock" with an exotic dancer at a local bar. The bar's location was dutifully tracked and, consequently, the salesman was fired. While that seems absolutely appropriate, it is not hard to anticipate other situations where Apple's secret tracking feature will lead to very unfortunate results, that are not as just.

Imagine the hapless victim of an auto accident, where someone hits them in a serious head on collision. While the car that caused the head on collision was going the wrong way, location data might show the victim was going five miles an hour over the speed limit at the time of the wreck. If the attorney for the wrong way driver's insurance company subpoenas the location data stored on the victims computer and their iPhone, they could then claim the illegal speed of the victim was a contributing factor to the wreck. This, to try get the insurance company off the hook for damages. You own an iPhone you lose. You own a piece of crap, throw away phone, you win.

I predict it will become a common question on interrogatories in lawsuits to ask if the party owns an iPhone or iPad. Data mining that compiled location information could make or break a legal case. Frankly, there are so many unanticipated consequences of insecure location data that are sure to come up, it is clear that location records should not be kept on insecure devices. There can be no doubt, iPhones, iPads and Macs are not "location data secure" and Apple is no longer to be trusted.

If Apple were to limit location data retention to no more than 10 minutes, that wouldn't be so invasive, but yet allow them to use location data. The parts of this whole thing that upset me are first, the lack of meaningful choice I had in participating in the data base, that sensitive insecure files were placed in my computer subjecting my data to misuse and that Apple had to be embarrassed into dealing with this issue. No location data need be stored on computers at all, if the data was automatically erased after uploading to Apple.  "Location Services" being turned off by the user ought to be observed and honored by Apple.  

Until Apple fixes this major security problem users can do the following to protect themselves:

Hook up your iPhone and, separately, your iPad to your computer you sync with.

Click the device bar on the left of the window.

3. In the grey bar on the left of the iTunes window scroll down to "options."

4. The fifth option listed is "Encrypt iPhone backup" click that option and you will be prompted to pick a password

5. Pick your password and follow the on screen instructions.

6. Then Click Sync at the bottom right side of the window.

At this point a bit longer than normal sync will occur as your Mac encrypts the backup data including your location logs.

This is not 100% reliable and encryption can be broken.  It does however make your location data more secure than Apple intended as a default.  This does not secure your data logs held on the iOS devices, which are only marginally more secure than the logs on your computer.  Other than completely erasing your iPhone and throwing away your backup files on your PC, you have done all you can do until Apple fixes this with a security update to both iTunes and the iOS platforms.

Currently, if you live in California, Nevada, Oregon, Washington State, Montana, Alaska, Hawaii or Idaho, the only way you can be sure your location data won't be legally taken from you by police without a warrant is to destroy your iPhone and iPad. In the US Ninth Circuit Court of Appeals' jurisdiction the Police have the right to "search" your iPhone without probable cause and without a warrant. A business iPhone or business iPad is not immune to the police either.  The only way to make your location history secure is really to have never compiled it in the first place or to securely erase the files, which it will take Apple to do. I have contacted Apple and demanded they take steps to erase my location records and to no longer keep such records.

The important legal issues of our "location privacy" and security for our mobile data will likely come before the US Supreme Court someday soon. The issue of the level of privacy of our data is critically important. Increasingly, data is held on tiny portable devices with enough memory to reveal far more about our personal lives than we would like.  

Apple can come out the protector of data privacy or be the worst offender. Right now the jury of public opinion would certainly go against them. Location data held by cell phone networks require a warrant to be released. A warrant requires probable cause be presented to a judge.  Reducing the level of privacy for our data to anything less, is simply not the American way.  Has Apple been breathing too much Chinese air?

That Greg's bitter Bite for today

(Greg Mills is currently a graphic and Faux Wall Artist in Kansas City. Formerly a new product R&D man for the paint sundry market, he holds 11 US patents. Greg is an Extra Class Ham Radio Operator, AB6SF, iOS developer and web site designer. He's also working on a solar energy startup using a patent pending process for turning waste dual pane glass window units into thermal solar panels used to heat water see: www.CottageIndustySolar.com Married, with one daughter, Greg writes for intellectual property web sites and on Mac/Tech related issues. See Greg's art web site at http://www.gregmills.info He can be emailed at gregmills@mac.com )

 

Community Search:
MacTech Search:

Software Updates via MacUpdate

Latest Forum Discussions

See All

Top Mobile Game Discounts
Every day, we pick out a curated list of the best mobile discounts on the App Store and post them here. This list won't be comprehensive, but it every game on it is recommended. Feel free to check out the coverage we did on them in the links... | Read more »
Price of Glory unleashes its 1.4 Alpha u...
As much as we all probably dislike Maths as a subject, we do have to hand it to geometry for giving us the good old Hexgrid, home of some of the best strategy games. One such example, Price of Glory, has dropped its 1.4 Alpha update, stocked full... | Read more »
The SLC 2025 kicks off this month to cro...
Ever since the Solo Leveling: Arise Championship 2025 was announced, I have been looking forward to it. The promotional clip they released a month or two back showed crowds going absolutely nuts for the previous competitions, so imagine the... | Read more »
Dive into some early Magicpunk fun as Cr...
Excellent news for fans of steampunk and magic; the Precursor Test for Magicpunk MMORPG Crystal of Atlan opens today. This rather fancy way of saying beta test will remain open until March 5th and is available for PC - boo - and Android devices -... | Read more »
Prepare to get your mind melted as Evang...
If you are a fan of sci-fi shooters and incredibly weird, mind-bending anime series, then you are in for a treat, as Goddess of Victory: Nikke is gearing up for its second collaboration with Evangelion. We were also treated to an upcoming... | Read more »
Square Enix gives with one hand and slap...
We have something of a mixed bag coming over from Square Enix HQ today. Two of their mobile games are revelling in life with new events keeping them alive, whilst another has been thrown onto the ever-growing discard pile Square is building. I... | Read more »
Let the world burn as you have some fest...
It is time to leave the world burning once again as you take a much-needed break from that whole “hero” lark and enjoy some celebrations in Genshin Impact. Version 5.4, Moonlight Amidst Dreams, will see you in Inazuma to attend the Mikawa Flower... | Read more »
Full Moon Over the Abyssal Sea lands on...
Aether Gazer has announced its latest major update, and it is one of the loveliest event names I have ever heard. Full Moon Over the Abyssal Sea is an amazing name, and it comes loaded with two side stories, a new S-grade Modifier, and some fancy... | Read more »
Open your own eatery for all the forest...
Very important question; when you read the title Zoo Restaurant, do you also immediately think of running a restaurant in which you cook Zoo animals as the course? I will just assume yes. Anyway, come June 23rd we will all be able to start up our... | Read more »
Crystal of Atlan opens registration for...
Nuverse was prominently featured in the last month for all the wrong reasons with the USA TikTok debacle, but now it is putting all that behind it and preparing for the Crystal of Atlan beta test. Taking place between February 18th and March 5th,... | Read more »

Price Scanner via MacPrices.net

AT&T is offering a 65% discount on the ne...
AT&T is offering the new iPhone 16e for up to 65% off their monthly finance fee with 36-months of service. No trade-in is required. Discount is applied via monthly bill credits over the 36 month... Read more
Use this code to get a free iPhone 13 at Visi...
For a limited time, use code SWEETDEAL to get a free 128GB iPhone 13 Visible, Verizon’s low-cost wireless cell service, Visible. Deal is valid when you purchase the Visible+ annual plan. Free... Read more
M4 Mac minis on sale for $50-$80 off MSRP at...
B&H Photo has M4 Mac minis in stock and on sale right now for $50 to $80 off Apple’s MSRP, each including free 1-2 day shipping to most US addresses: – M4 Mac mini (16GB/256GB): $549, $50 off... Read more
Buy an iPhone 16 at Boost Mobile and get one...
Boost Mobile, an MVNO using AT&T and T-Mobile’s networks, is offering one year of free Unlimited service with the purchase of any iPhone 16. Purchase the iPhone at standard MSRP, and then choose... Read more
Get an iPhone 15 for only $299 at Boost Mobil...
Boost Mobile, an MVNO using AT&T and T-Mobile’s networks, is offering the 128GB iPhone 15 for $299.99 including service with their Unlimited Premium plan (50GB of premium data, $60/month), or $20... Read more
Unreal Mobile is offering $100 off any new iP...
Unreal Mobile, an MVNO using AT&T and T-Mobile’s networks, is offering a $100 discount on any new iPhone with service. This includes new iPhone 16 models as well as iPhone 15, 14, 13, and SE... Read more
Apple drops prices on clearance iPhone 14 mod...
With today’s introduction of the new iPhone 16e, Apple has discontinued the iPhone 14, 14 Pro, and SE. In response, Apple has dropped prices on unlocked, Certified Refurbished, iPhone 14 models to a... Read more
B&H has 16-inch M4 Max MacBook Pros on sa...
B&H Photo is offering a $360-$410 discount on new 16-inch MacBook Pros with M4 Max CPUs right now. B&H offers free 1-2 day shipping to most US addresses: – 16″ M4 Max MacBook Pro (36GB/1TB/... Read more
Amazon is offering a $100 discount on the M4...
Amazon has the M4 Pro Mac mini discounted $100 off MSRP right now. Shipping is free. Their price is the lowest currently available for this popular mini: – Mac mini M4 Pro (24GB/512GB): $1299, $100... Read more
B&H continues to offer $150-$220 discount...
B&H Photo has 14-inch M4 MacBook Pros on sale for $150-$220 off MSRP. B&H offers free 1-2 day shipping to most US addresses: – 14″ M4 MacBook Pro (16GB/512GB): $1449, $150 off MSRP – 14″ M4... Read more

Jobs Board

All contents are Copyright 1984-2011 by Xplain Corporation. All rights reserved. Theme designed by Icreon.