Greg's bite: Location iNsecure, a Rotten Apple can't be trusted
TweetFollow Us on Twitter

Greg's bite: Location iNsecure, a Rotten Apple can't be trusted

By Greg Mills

Steve Jobs is the new evil Big Brother. I would like to retract my statement posted November 21, 2010: "Jobs and Apple gone evil? Not so." Remember the iconic Apple commercial of the woman running down the aisle and throwing a hammer at the theater screen picture of big brother (as in the Orwellian novel "1984")?   The evil dictator's image was shattered and we all cheered. Could Steve Job's face become the modern big brother image? This sort of location tracking that came to light last week, previously reserved for the most dangerous criminals has been applied to us all by Apple, and for what? So that Apple could sell stinking pizzas!?

As news of the audaciousness of Apple secretly tracking and recording the detailed movements of everyone who innocently purchased the hugely popular iPhone and iPad sinks in, the question of why Apple did it comes to mind.  While some still want to give Apple the benefit of the doubt, the evidence is overwhelming that the invasion of our privacy was intentional. Apple's engineers are way too methodical to have "accidentally" stored and upload detailed location data compiled on every user of the iOS, for at least a year and likely longer.

Compared to the tenuous relationship Microsoft has with its PC consumers, Apple has historically had a virtual love affair with its faithful. That legendary trust, has been built for years among long term Mac users, who have stood faithfully by their Apple computers when faced with all manor of platform marginalization from the Windows PC world. Thus, this serious betray of our trust is particularly hard to take. Labeled an "odd man out" for years for insisting on using a Mac instead of a PC, I have previously been faced with having to provide my own computer at work, since the company I was with at the time, "didn't support the Mac platform."  Ironically, the art department was able to demand and get a Mac, but as Product Marketing Manager I was forced to use my personal MacBook at work.  

As Apple has grown over the last few years, a sort of corporate mindset corruption has apparently occurred: The fanatical Apple user experience be damned, there is money to be made! Keep in mind, the change was slow and came in incremental stages, but the cynical motives at 1 Infinity Loop can no longer be denied. A fundamental change in corporate philosophy has taken place at Apple.  

Remember the frog placed in cool water on a stove will sit and be cooked to death as the water temperature slowly rises. Dropping that same frog into hot water would have gotten an immediate violent response. It feels like very hot water was just dumped on me in my relationship with Apple. Can we trust Apple to keep our data in the cloud without violating our privacy for some corporate advantage? I don't think so. Who knows how they might abuse that technology?

Apple recently has announced that it is adding a "do not track" feature to Safari to protect the privacy of web surfers; ironically, the much more invasive detailed location tracking features of iPhones and iPads was secretly still in use. I don't think anything would have changed had Apple not been caught with its pants down. I think Apple will be forced to stop tracking its consumers. A normally masterful control of the media by Apple can't control the bad spin in the press over this issue. Apple didn't come forward on its own and offer an opt out for the tracking; they were caught doing it without a meaningful choice by the consumer. I figure I have my ear to the ground on Apple issues, but I will have to admit this shocked and surprised me.

Apple certainly made the decision at the highest levels to get into the digital advertising business and to leverage the Apple platforms to accomplish that, apparently at any cost. When one looks at Google, they are doing a lot of things that make money, but the real serious money they make comes from advertising. Targeted advertising is far more lucrative and profitable than standard broad based advertising. Apple saw that, and the iAd concept was developed.  

If you run a pizza shop, for example, the notion of having an electronic full color interactive digital coupon pop up on cell phones as someone enters a local "geo-fenced" zone, is worth far more than broad un-targeted advertising programs going to hundreds of times more "unfocused consumers".  

Let's say the geo-fenced area is 1/4 of a mile each way along a major street your pizza shop is located on. If you could target potential pizza customers who are being tracked by their phones to those nearby locations, traveling along that road, during the hours between 11 am and 8 pm with a $3.99 medium pizza electronic coupon offer, that would be worth a lot of money to you. If that customer, has also been tracked over a long period of time and has a history of stopping at other pizza shops in town, that is also a value building element to location based advertising. Long term location history has tremendous value to advertising companies, apparently more than the value of customer loyalty to Apple.

The potential for adding the "electronic wallet feature" to future iPhones will leverage the targeting advertising potential even more. People who historically spend money at other pizza shops using their iPhones to pay are certainly choice customers to send electronic coupons to should they venture into your geo-fenced zone. It has been rumored that Apple plans to add an RFID chip to iPhones, that chip would support a "swipe to charge" feature to your cell phone. The iPhone would deduct the pizza charges electronically from your account and also make a note that you buy pizzas. Add that habit information to knowing where you are, and you can see where they are going with this.

It is easy to see why Apple decided to get into the electronic advertising business. The big idea is to push targeted electronic ads to the millions of consumers who also happen to own iPhones and iPads. According to recent polls, a magnitude of half of the current users of iPhones and iPads have no major objection to their locations being tracked by Apple. That however leaves half of us who are infuriated and feel seriously betrayed. I suspect the ranks of the betrayed will increase as the unexpected ramifications of insecure location data becomes better understood. I think that is why Apple didn't disclose more fully what they were doing. Some of us would vocally object if we knew. 

An invasion of privacy as a generalized notion in society rises to a fairly low level of concern. When an invasion of privacy actually happens to you with an unexpected problem resulting, the level of anger suddenly becomes much greater. The result of "location history insecurity" can be individually quite profound. Apple doesn't seem to care when the privacy of Apple individual users are weighed against the potential money they can make selling location based ads. Some years back, the calculus would have been much different. I thought Apple cared about me individually as an avid long term Mac fan. Now I am sure they really don't care about me, nearly as much as I thought they did. 

Beyond  invasion of privacy issues, the lack of meaningful notice that such detailed tracking and location recording would be the default and that a way to opt out of tracking wasn't even offered is a major issue. If half the users of iPhones were willing to submit their locations to Apple why would they track everyone regardless of they way they felt about it? As I understand it even turning off locations services didn't prevent the tracking and records generation based upon tower and Wi-Fi information. Turning off location services ought to mean you don't want to be tracked, period. 
      
As I predicted in Friday's post, a class action lawsuit will certainly be filed over this. A complaint was previously filed in San Jose California by user Jonathan Lalo seeking class action status on questionable Apple location tracking policies. Filed in December of last year, the suit was originally tailored just to take Apple to task for certain iOS apps that used location services without proper notice to consumers. I suspect that lawsuit will be modified to go after Apple for the more pervasive and general secret tracking feature on all iOS devices. See http://www.tgdaily.com/business-and-law-features/53245-apple-sued-over-data-tracking .

There is also the strong possibility that fresh federal lawsuits will be filed, specifically due to the recent secret iOS tracking revelations.  The basis of the likely class action suit is certain to be upon a combination of the violation of existing privacy laws and the lack of meaningful notice that such detailed tracking was taking place and that secret long term records were being kept. 

How can Apple claim the tracking data is "not personably identifiable" when a complete unencrypted record is found on all your personal Apple devices, which are subject to theft, hacking and loss? Give me a blank disk and five minutes access to someones Mac, I will walk away with a complete record of "location data" for every iOS device that syncs with that computer. You can also anticipate that I can figure out who the computer belongs to. So much for the notion of the location logs not being identifiable.   

Further, it wasn't ever disclosed that the computer the iOS devices sync with would also create and maintain a persistent location log going back to the very first day the iOS device was activated. While the attorneys at Apple are sure to yawn at "just another lawsuit," the implications of these suits should be meaningful to Apple.  When long time Apple faithful are so angry they are suddenly willing to sue, can Apple just shrug that off? The old Apple wouldn't want that. I am not so sure about the new Apple. 

I am of the opinion that Apple will move to create an opt in/opt out location tracking history feature common to both the Mac OS and the iOS platforms that will allow existing tracking records to be erased and no longer stored. I am convinced that while the pressure of lawsuits might be a minor factor in forcing them to amend their platforms, the real reason they will move on this issue will be the potential of lost market share. This situation is clearly going to hurt Apple sales of both devices to new users and retard sales to established upgrade customers. I certainly will not replace my aging iPhone 3Gs or iPad 1 or sign up for another year as an iOS developer until I can be darn sure Apple won't continue to abuse my trust.

Apple has been working hard to convince the enterprise and even the military that iOS devices are secure enough to trust with sensitive data. This breech of trust that merely infuriates civilians is much more of a dangerous security threat to potential enterprise and military users. Apple devices are anything but "location data secure." This is a very important defect in data security and is certain to be noticed by decision makers in business and the military.

Imagine an iPhone used by the military being captured and location files downloaded into a Mac laptop. Then the movements of that particular soldier can be graphically mapped showing troop movements in vidid detail, complete with time/date stamps. This sort of compiled location information would be an absolute gold mine to the other side.  Using detailed location data would give an enemy the exact GPS setting for missiles or bombs which would hit the barracks where the soldiers sleep. It also could potentially give away current troop concentrations by remote access to location data hacked over a cellular network.  

What business will be willing to risk the location data for its executive employees falling into the hands of competitors? What unanticipated consequences will befall users of iOS devices, simply due to trusting Apple to do no harm to them?  

I recently did a Faux art job for a customer who personally knew someone who had been fired due to location data stored on a company cell phone. It seems this salesman was spending time "on the clock" with an exotic dancer at a local bar. The bar's location was dutifully tracked and, consequently, the salesman was fired. While that seems absolutely appropriate, it is not hard to anticipate other situations where Apple's secret tracking feature will lead to very unfortunate results, that are not as just.

Imagine the hapless victim of an auto accident, where someone hits them in a serious head on collision. While the car that caused the head on collision was going the wrong way, location data might show the victim was going five miles an hour over the speed limit at the time of the wreck. If the attorney for the wrong way driver's insurance company subpoenas the location data stored on the victims computer and their iPhone, they could then claim the illegal speed of the victim was a contributing factor to the wreck. This, to try get the insurance company off the hook for damages. You own an iPhone you lose. You own a piece of crap, throw away phone, you win.

I predict it will become a common question on interrogatories in lawsuits to ask if the party owns an iPhone or iPad. Data mining that compiled location information could make or break a legal case. Frankly, there are so many unanticipated consequences of insecure location data that are sure to come up, it is clear that location records should not be kept on insecure devices. There can be no doubt, iPhones, iPads and Macs are not "location data secure" and Apple is no longer to be trusted.

If Apple were to limit location data retention to no more than 10 minutes, that wouldn't be so invasive, but yet allow them to use location data. The parts of this whole thing that upset me are first, the lack of meaningful choice I had in participating in the data base, that sensitive insecure files were placed in my computer subjecting my data to misuse and that Apple had to be embarrassed into dealing with this issue. No location data need be stored on computers at all, if the data was automatically erased after uploading to Apple.  "Location Services" being turned off by the user ought to be observed and honored by Apple.  

Until Apple fixes this major security problem users can do the following to protect themselves:

Hook up your iPhone and, separately, your iPad to your computer you sync with.

Click the device bar on the left of the window.

3. In the grey bar on the left of the iTunes window scroll down to "options."

4. The fifth option listed is "Encrypt iPhone backup" click that option and you will be prompted to pick a password

5. Pick your password and follow the on screen instructions.

6. Then Click Sync at the bottom right side of the window.

At this point a bit longer than normal sync will occur as your Mac encrypts the backup data including your location logs.

This is not 100% reliable and encryption can be broken.  It does however make your location data more secure than Apple intended as a default.  This does not secure your data logs held on the iOS devices, which are only marginally more secure than the logs on your computer.  Other than completely erasing your iPhone and throwing away your backup files on your PC, you have done all you can do until Apple fixes this with a security update to both iTunes and the iOS platforms.

Currently, if you live in California, Nevada, Oregon, Washington State, Montana, Alaska, Hawaii or Idaho, the only way you can be sure your location data won't be legally taken from you by police without a warrant is to destroy your iPhone and iPad. In the US Ninth Circuit Court of Appeals' jurisdiction the Police have the right to "search" your iPhone without probable cause and without a warrant. A business iPhone or business iPad is not immune to the police either.  The only way to make your location history secure is really to have never compiled it in the first place or to securely erase the files, which it will take Apple to do. I have contacted Apple and demanded they take steps to erase my location records and to no longer keep such records.

The important legal issues of our "location privacy" and security for our mobile data will likely come before the US Supreme Court someday soon. The issue of the level of privacy of our data is critically important. Increasingly, data is held on tiny portable devices with enough memory to reveal far more about our personal lives than we would like.  

Apple can come out the protector of data privacy or be the worst offender. Right now the jury of public opinion would certainly go against them. Location data held by cell phone networks require a warrant to be released. A warrant requires probable cause be presented to a judge.  Reducing the level of privacy for our data to anything less, is simply not the American way.  Has Apple been breathing too much Chinese air?

That Greg's bitter Bite for today

(Greg Mills is currently a graphic and Faux Wall Artist in Kansas City. Formerly a new product R&D man for the paint sundry market, he holds 11 US patents. Greg is an Extra Class Ham Radio Operator, AB6SF, iOS developer and web site designer. He's also working on a solar energy startup using a patent pending process for turning waste dual pane glass window units into thermal solar panels used to heat water see: www.CottageIndustySolar.com Married, with one daughter, Greg writes for intellectual property web sites and on Mac/Tech related issues. See Greg's art web site at http://www.gregmills.info He can be emailed at gregmills@mac.com )

 
AAPL
$118.72
Apple Inc.
+1.12
MSFT
$47.50
Microsoft Corpora
+0.03
GOOG
$539.23
Google Inc.
-1.85

MacTech Search:
Community Search:

Software Updates via MacUpdate

RapidWeaver 6.0.3 - Create template-base...
RapidWeaver is a next-generation Web design application to help you easily create professional-looking Web sites in minutes. No knowledge of complex code is required, RapidWeaver will take care of... Read more
iPhoto Library Manager 4.1.10 - Manage m...
iPhoto Library Manager lets you organize your photos into multiple iPhoto libraries. Separate your high school and college photos from your latest summer vacation pictures. Or keep some photo... Read more
iExplorer 3.5.1.9 - View and transfer al...
iExplorer is an iPhone browser for Mac lets you view the files on your iOS device. By using a drag and drop interface, you can quickly copy files and folders between your Mac and your iPhone or... Read more
MacUpdate Desktop 6.0.3 - Discover and i...
MacUpdate Desktop 6 brings seamless 1-click installs and version updates to your Mac. With a free MacUpdate account and MacUpdate Desktop 6, Mac users can now install almost any Mac app on macupdate.... Read more
SteerMouse 4.2.2 - Powerful third-party...
SteerMouse is an advanced driver for USB and Bluetooth mice. It also supports Apple Mighty Mouse very well. SteerMouse can assign various functions to buttons that Apple's software does not allow,... Read more
iMazing 1.1 - Complete iOS device manage...
iMazing (was DiskAid) is the ultimate iOS device manager with capabilities far beyond what iTunes offers. With iMazing and your iOS device (iPhone, iPad, or iPod), you can: Copy music to and from... Read more
PopChar X 7.0 - Floating window shows av...
PopChar X helps you get the most out of your font collection. With its crystal-clear interface, PopChar X provides a frustration-free way to access any font's special characters. Expanded... Read more
Carbon Copy Cloner 4.0.3 - Easy-to-use b...
Carbon Copy Cloner backups are better than ordinary backups. Suppose the unthinkable happens while you're under deadline to finish a project: your Mac is unresponsive and all you hear is an ominous,... Read more
ForeverSave 2.1.3 - Universal auto-save...
ForeverSave auto-saves all documents you're working on while simultaneously doing backup versioning in the background. Lost data can be quickly restored at any time. Losing data, caused by... Read more
Voila 3.8.1 - Capture, annotate, organiz...
Voila is a screen-capture, recording, and annotation tool that is a full-featured replacement for Mac's screen-capture and screen-recording capabilities. It has a large and robust set of editing,... Read more

Latest Forum Discussions

See All

Tales from the Borderland​s Will be Comi...
Tales from the Borderland​s Will be Coming to iOS by the End of the Year Posted by Jessica Fisher on November 26th, 2014 [ permalink ] Telltale Games has announced | Read more »
Sunburn! Review
Sunburn! Review By Campbell Bird on November 26th, 2014 Our Rating: :: DON'T DIE ALONEUniversal App - Designed for iPhone and iPad Platform through the depths of space to make sure your entire crew dies together in this satisfying... | Read more »
Black Friday has Started Early – Lots an...
It’s almost turkey time! Which means lots and lots of food but also lots and lots of sales. Some sales have even started a few days early, which is why we’ve put together a list of iOS games that are currently discounted (sometimes by a lot).... | Read more »
Loose Leaf Review
Loose Leaf Review By Jennifer Allen on November 26th, 2014 Our Rating: :: SIMPLE SKETCHINGiPad Only App - Designed for the iPad Sketch out ideas with simple drawing tools, courtesy of Loose Leaf.   | Read more »
Screeny (Utilities)
Screeny 1.0 Device: iOS iPhone Category: Utilities Price: $.99, Version: 1.0 (iTunes) Description: Screeny is an utility app that helps you save space consumed by screenshots. It screens your camera roll and helps you to filter and... | Read more »
Tilt to Live Bundle Set to Arrive This T...
Tilt to Live Bundle Set to Arrive This Thanksgiving Posted by Ellis Spice on November 25th, 2014 [ permalink ] One Man Left has unveiled an upcoming Tilt to Live bundle, allowing players to get the series for a di | Read more »
BattleLore: Command (Entertainment)
BattleLore: Command 1.0 Device: iOS Universal Category: Entertainment Price: $9.99, Version: 1.0 (iTunes) Description: ***NOTE: Compatible with iPad 2/iPad mini, iPod touch 5 and up and iPhone 4S and up – WILL NOT RUN ON EARLIER... | Read more »
Weather Or Not Review
Weather Or Not Review By Jennifer Allen on November 25th, 2014 Our Rating: :: STYLISH WEATHER REPORTINGiPhone App - Designed for the iPhone, compatible with the iPad Check the weather quickly and conveniently with Weather or Not... | Read more »
The All-New Football Manager Handheld 20...
The All-New Football Manager Handheld 2015 is Available Now Posted by Jessica Fisher on November 25th, 2014 [ permalink ] Universal App - Designed for iPhone and iPad | Read more »
Six iOS Games to Get You Ready for Thank...
Image Source: Friends Wiki At this point in the month, you or at least a few people you know are probably getting ready to scramble around (or are already scrambling around) for Thanksgiving Dinner. It’s a hectic day of precise oven utilization, but... | Read more »

Price Scanner via MacPrices.net

Why iPhone 6 Tablet/Laptop Cannibalization Is...
247wallst.com blogger Douglas A. McIntyre noted last week that according to research posted on the Applovin blog site the iPhone 6 is outselling the iPhone 6 Plus by a wide margin . Hardly a surprise... Read more
Worldwide Tablet Growth Expected to Slow to 7...
The global tablet market is expected to record massive deceleration in 2014 with year-over-year growth slowing to 7.2%, down from 52.5% in 2013, according to a new forecast from International Data... Read more
Touchscreen Glove Company Announces New Produ...
Surrey, United Kingdom based TouchAbility specializes in design and manufacture of a wide variety of products compatible with touchscreen devices including smartphones, tablets and computers. Their... Read more
OtterBox Alpha Glass Screen Protectors for iP...
To complement the bigger, sharper displays on the latest Apple devices, OtterBox has introduced Alpha Glass screen protectors to the iPhone 6 and iPhone 6 Plus. The fortified glass screen protectors... Read more
Early Black Friday Mac Pro sale, 6-Core 3.5GH...
 B&H Photo has the 6-Core 3.5GHz Mac Pro on sale today for $3499 including free shipping plus NY sales tax. Their price is $500 off MSRP, and it’s the lowest price available for this model from... Read more
Early Black Friday sale price: 15-inch 2.2GHz...
 B&H Photo has the 2014 15″ 2.2GHz Retina MacBook Pro on sale today for $1699.99. Shipping is free, and B&H charges NY sales tax only. Their price is $300 off MSRP, equalling Best Buy’s price... Read more
13-inch 2.5GHz MacBook Pro (refurbished) avai...
The Apple Store has Apple Certified Refurbished 13″ 2.5GHz MacBook Pros available for $170 off the cost of new models. Apple’s one-year warranty is standard, and shipping is free: - 13″ 2.5GHz... Read more
Early Black Friday iPad mini 3 sale: $75 off...
 Best Buy has iPad mini 3s on sale for $75 off MSRP on their online store for a limited time. Choose free shipping or free local store pickup (if available). Sale prices available for online orders... Read more
Early Black Friday MacBook Pro sale: 15-inch...
 Best Buy has posted early Black Friday prices on 15″ Retina MacBook Pros, with models on sale for $300 off MSRP on their online store for a limited time. Choose free local store pickup (if available... Read more
A9 Chips Already?
It’s barely more than a couple of months since Apple got the first A8 systems-on-chip into consumer hands, but rumor and news focus is already turning to the next-generation A9 SoC. Apple Daily... Read more

Jobs Board

*Apple* Solutions Consultant (ASC) - Apple (...
**Job Summary** The ASC is an Apple employee who serves as an Apple brand ambassador and influencer in a Reseller's store. The ASC's role is to grow Apple Read more
Senior Event Manager, *Apple* Retail Market...
…This senior level position is responsible for leading and imagining the Apple Retail Team's global event strategy. Delivering an overarching brand story; in-store, Read more
*Apple* Retail - Multiple Positions (US) - A...
Sales Specialist - Retail Customer Service and Sales Transform Apple Store visitors into loyal Apple customers. When customers enter the store, you're also the Read more
*Apple* Solutions Consultant (ASC) - Apple (...
**Job Summary** The ASC is an Apple employee who serves as an Apple brand ambassador and influencer in a Reseller's store. The ASC's role is to grow Apple Read more
*Apple* Solutions Consultant (ASC) - Apple (...
**Job Summary** The ASC is an Apple employee who serves as an Apple brand ambassador and influencer in a Reseller's store. The ASC's role is to grow Apple Read more
All contents are Copyright 1984-2011 by Xplain Corporation. All rights reserved. Theme designed by Icreon.