Bose headphones spy on listeners: lawsuit (2017)
reuters.com
reuters.com
"The court dismissed Zak’s novel wiretap and eavesdropping claims, writing that the complaint failed to adequately allege that Bose is not a party to communication, as is necessary for violations of these statutes. “ … [T]he relevant inquiry,” the court wrote, “is whether the defendant is a participant in the conversation, as opposed to a nonparticipant that uses other means to gain access to – i.e., intercept – the communication.” Bose wasn’t an intruding third party, so this line of attack was shut down.
Nonetheless, the unjust enrichment and Illinois state consumer fraud charges survived. And, to make things a little more interesting for the defendant, the court left the door open for Zak to file again under the Wiretap Act if he could prove “that Bose is in fact not a party to the communication or that Bose, while a party, nevertheless intercepted a communication with the purpose of committing a crime or tort independent from the alleged interception.”"
https://www.lexology.com/library/detail.aspx?g=5499bec3-8a87...
I was assuming it would be thrown out because they only collected metadata and if they didn’t pull full audio that they didn’t meet a required element.
Luckily the wording implies that it’s not that the judge found from the evidence that they were an invited party, just that the claim failed to properly lay the foundation in their briefs?
I hope they refile.
> The alleged eavesdropping would deliver user information – including song selections . . .
[GP's source]
---
Honestly I think it might be worth looking into the idea of metadata collection as eavesdropping. Unless there's an implicit technical requirement for data, the company should need to explicitly request it.
For phone lines it's obvious why the service provider is party to the communications:
caller --> switching equipment --> callee
The bose situation is more: user --> bluetooth --> headphones
|
+--> bose
Though this sort of ruling might just drive everything to an even more disgusting state of centralized services so that companies can claim an implicit technical need for data.The Wiretap Act complaint has bigger problems.
“‘Electronic communication’ is defined, in relevant part, as ‘any transfer of signs, signals, writing, images, sounds, data, or intelligence of any nature transmitted in whole or in part by a wire, radio, electromagnetic, photoelectronic or photooptical system that affects interstate or foreign commerce . . . .’ 18 U.S.C. § 2510(12)” [1]. It would be tough to claim the Bluetooth connection between the phone and headphones are engaged in interstate commerce.
“Moreover, Zak’s Brief in Opposition to the Motion to Dismiss (‘Opposition Brief’) further clarifies the FAC’s allegations6 and makes clear that in fact ‘Bose Connect is part of the listener to music provider communication[,]’ indeed ‘the App is supposed to function as a leg in the listener-to-music provider communication pathway—one that can be used to request new material or view audio track information.’ (Opp. Br. at 7 n.5, 8.) The Opposition Brief further explains that ‘information is . . . routed to the App where track information—e.g. song name, album, and artist information—is displayed.’ (Id. at 1.) It is clear from the facts alleged in the FAC, and clarified in the Opposition Brief, that the App is in fact a known participant in—and intended recipient of—the communication of the Media Information.”
[1] https://f.datasrvr.com/fr1/319/48563/Bose_Memo_and_Order.pdf
Stating that this is "their design philosophy" is a stretch here. I realize Sony doesn't have a stellar track record but in their defense if you don't use 'Adaptive Sound Control' the app does not and will not try to enable Location access unless you turn said feature on and the app doesn't already have access.
So, no - you don't need to pay for the convenience of Sony's app by allowing Location access as it's not required but for a singular feature that is fundamentally based around setting profiles based on your location.
I reinstalled the app to see if I was misremembering it. The app requests for always on location information upon installation and pairing with the headphones. The garden path in the UX of the app is to allow location access. If the user chooses to not allow location access by tapping the tiny "Later" button, the main screen prominently features a Switch control (which is off) for Adaptive Sound Control, tempting the user to toggle it on, which requests always on location access. Given all of this, it's very difficult to interpret this "feature" in a favorable light.
Fortunately, the app's privacy policy[1] does not seem to mention anything about them collecting location information (but they do claim to collect "country or region"). On the other hand, the manual for the app[2] also has no mention of it requesting always on location access either, which doesn't inspire much confidence. Not to mention the 27 month data retention policy and the policy of sharing with their "affiliates".
After having read the privacy policy, I'm glad I chose not to use the app and will continue to do so.
[1]: https://musiccenter-cdn.meta.ndmdhs.com/headphones/pp/201903... [2]: https://helpguide.sony.net/mdr/hpc/v1/en/index.html
What would you rather they do? They ask for permission for a specific feature and when denied, the feature is turned off. When you try to turn on the feature, it requests access for that feature. It sounds like it works exactly as it should.
I would rather that they document why they need background location access and not try to hoodwink their users into granting them carte blanche access to the users' location data. There's a fairly established pattern in mobile apps where they show a screen informing the user of the reasons why an app needs location access before requesting it from the OS. And that isn't the case with the app in question. Nowhere in their product documentation (for both the app and the headphones) do they mention that their product needs background location access.
Also, let's not forget the context of the post here. The Bose Connect app (at least on iOS) does not demand access to the user's location. They got sued for lesser privacy violation (in my subjective opinion) and rightly so. Any app demanding background location access, especially an app for a pair of headphones is a serious concern, IMO.
The other commenter in this thread seems to be insinuating that I have a bias against Sony. But that's certainly not the case. I've spent a lot of money on Sony's mirrorless cameras and lenses and continue to do so. Sony undoubtedly makes great hardware, but on the other hand, privacy is also very important to many of us. One could argue that privacy is far more important than the fancy hardware.
Finally, coming back to the "feature" in question, "Adaptive Sound Control". The feature seems to be built around classifying whether the wearer of the headphones is standing still, or walking or running or using a mode of transport and applying the user selected profile based on the activity. Couldn't this be implemented in a much more efficient manner in hardware with an accelerometer in the headphones? I understand that this would mean a slightly reduced battery life on the headphones for people using the feature, but would be a better trade off, IMO. And yes, decisions like this are a product of a company's design philosophy.
I'm not sure you are understanding the feature. It allows you to set profiles for your location automatically. Like if you're at home maybe you care more about ambient noise while cancelling is enabled. Maybe while you're at work you want to dial it down. Yes, you can switch between profiles in other ways but this allows your phone to do it automatically for you. The app does not "demand" access, I wish you'd stop saying this because it is not true. Again if you do not use the feature it, literally, will never ask you for location permissions until you try to turn the feature that requires it on.
> Finally, coming back to the "feature" in question, "Adaptive Sound Control". The feature seems to be built around classifying whether the wearer of the headphones is standing still, or walking or running or using a mode of transport and applying the user selected profile based on the activity. Couldn't this be implemented in a much more efficient manner in hardware with an accelerometer in the headphones? I understand that this would mean a slightly reduced battery life on the headphones for people using the feature, but would be a better trade off, IMO. And yes, decisions like this are a product of a company's design philosophy.
You're wrong here. Maybe try to understand the feature before making a bunch of incorrect assumptions. You think an accelerometer is going to be able to differentiate your work and home location? No. It's a pair of headphones and a feature that has been blown way out of proportion with your strawman. Finally, a feature does not a company's design philosophy make as, again, you assume here with absolutely zero basis to back up your argument. Not only have you failed to show how this feature is ill used by Sony you've also failed to comprehend what it actually is or how it's used.
Perhaps I am. This seems like right occasion to pull out my trusty old iPhone 6S Plus from my drawer that I keep around for testing dodgy apps.
I installed the latest version of the "Sony | Headphones Connect" from the iOS App Store on the aforementioned phone with a throwaway app store account. Also, I allowed it the full location access that it had been asking for, to enable the "feature". I took screenshots of every screen along the way. I've uploaded them here[1]. You'll only need to see the first 4 screenshots there to see what I'm talking about. The screenshots are in reverse chronological order and have been cropped to remove the iOS status bar.
As evidenced by the screenshots, the only modes the "Ambient Sound Control" "feature" is able to differentiate in between are "Transport", "Running", "Walking", and "Staying". Now, it's amply evident that you're either lying or using some special version of the app that isn't publicly available and allows your pair of headphones to distinguish between when you're using them at home and when you're using them at work.
Also, to cite from another contradictory comment[2] of yours on this thread: > I've never allowed any permissions for this app and have yet to have any functionality diminished.
If you've never allowed permissions for this app, then how did jump to the false conclusion about the app being able to differentiate your work and home location? It looks like the only way to ascertain that would be to allow location access to the app.
The certitude with which you state your opinions on this thread and the extent to which you're willing to ignore the facts, makes me suspicious of your motives here.
Also, can I even buy a sound bar for my TV that doesn't listen to me and need an internet connection these days... It's unreal the unneeded complexity and bullshit they put in some electronics.
The real heroes the world needs are just independent founders that use slow growth over several generations and never sell the business, thus minimizing incentives other than having a lifestyle business and making great stuff. But the money is just too tempting eventually, or the business just isn't feasible at that scale.
IIRC, and I'm quite confident about this particular one, ads used to be served based on the site you were visiting or the search had typed.
Some people hate all ads.
For me I felt old google ads were OK.
Some people will say this isn't a good enough business model and to that I'll point out that google was widely profitable back then as well, again IIRC.
Strangely enough, ads in feeds like Facebook, LinkedIn, or Twitter don’t annoy me as much.
I also think the ads in the iOS App Store are horrible.
The main obstacle will be the convoluted IP mess user-hostile companies create, through laws preventing you from reversing and replacing the firmware, and through tying the hardware to an Internet service.
People have done studies on how much people will pay for minimally permissioned apps. It's basically nothing.
On that subject, I really wish Apple would allow me to use photos app to sync with a network share.
Note: Autotransfer on iOS is "location based transfer" only.
I won’t use it because of that. But thanks.
Transfers original files and preserves EXIF metadata including location data in all directions.
What is “location based transfer”?
If you are worried about the privacy implications, when an app tells iOS that it wants to be notified when it is in a certain location. It doesn’t get your location until you are there. It doesn’t have the ability to continuously track you.
I did too, and I stopped using them largely because of the amount of information the app collects. If this lawsuit gets a class certified, an analog for Sony might be something I look into.
https://stackoverflow.com/questions/33045581/location-needs-...
Due to the bad layering of the BLE model it’s next to impossible to actually hide from the app the data of what peers are around the device, while still allowing the app to communicate over BLE. This isn’t true of regular Bluetooth, but BLE is solving a harder problem, sort of like how WebRTC is solving a harder problem than HTTP.
Still, you’d hope they’d come up with some way to obscure the peer BT MAC addresses or something. Maybe an approach like Apple used with device IDs, where each app sees the device ID hashed with a per-app salt—each app would see a separate list of virtual BT MACs that, when it sent messages to, the OS would translate back to the real MACs. Like BT “file handles”, almost.
Same scenario about PayPal offering that I receive receipts in Messenger or Deliveroo offering WhatsApp notifications.
Same for adding location to photos. On iOS you can deny the permission and still enter location manually. On Android, you can't enter a location manually unless you give the app location permission. Totally not useful, either - location info is already embedded in the photo and I really don't need the help of GPS to determine my current location.
On a similar note though, I just tried sending a tracking link for my Uber trip to my friend, and it tried to get contacts access permission (which I obviously denied) before giving me the link. I guess it preys on the fact that most people wouldn’t risk denying it thinking it won’t allow them to use the feature otherwise. Uber doesn’t seem to have anything to do with ads/stalking but it seems like nothing is safe in this day and age.
See also ninety-plus percent of existing javascript, and literally the entire existence of intel management engine.
I’m happy to report there’a a toggle in the app’s settings and that it now clearly indicates it sends the song data for diagnostic purposes if checked. (And yes, I disabled it.)
The future sucks.
It seems the goal of most companies is to create a seemingly legitimate need for apps/permissions, no matter how convoluted, just so they can get access to data.
I never installed the app purely because I’ve never had a reason. Then the spying stuff just reinforced my hatred of every single device these days needing one. I now specifically look for hardware devices that don’t need an app or cloud service account.
My headphones will sometimes automatically switch between sources when it recognizes I'm using another device. Like when I'm listening to music on my PC, if I start browsing my phone I'll start heading audio from it instead.
Google now has the data and technology to spy on everyone using their wearables. Including people who never owned or used a Google product.
Google clearly wants this, but can't do anything overt about it without attracting bad press. So they attached location permissions to a new technology they know everybody will use eventually.
Basically what they say is that this information can theoretically be calculated so we demand you just give it (and some more) to us.
https://en.wikipedia.org/wiki/Tile_(company)
> The application can locate Tiles beyond the 100-foot Bluetooth range, using "crowd GPS": if an item with an attached Tile device is reported lost and comes within range of another user's Tile application, the nearby user's application will send the item's owner an anonymous update of that item's location.
Permissions ideally shouldn't overlap, but in this case, they somewhat do.
--
[0] - and given the disastrous lack of ethics in the tech sector, it's very likely it will do that, or one of 30 adtech libraries it includes will.
See my other comments.
Its just that I think that an app/hardware integration ethic definitely has a place in the world. For example, hardware which works with Apple, without allowing third-party (not even Apple) involvement, is a battle being fought.
Hardware vendors should be encouraged to ensure their hardware remains useful for generations, in my opinion. Apps always go stale while the hardware remains operational.
Of course: none of this forgives the vendors using it to spy on its customers.
Hardware like this, anyway imho at this market, is a platform battleground. In all honesty, we have more computer vendors battling it out now, than ever before.
More than likely, putting "compatible with iOS" on the box of an expensive speaker means more shelf-shopping customers. Alas, Bose and Apple probably have, at least, MFI-level involvement...
This is why I have never used the Bluetooth features on my QC35s. They're mostly dumb headphones to me since I won't accept their user agreement. This seems counterproductive for the company, unless they simply don't care about user privacy and expect users to roll over.
I truly do believe, as do you, that the TOS and Warranty world is another desperate subject from where the execs/lawyers/owners of the company desire to eek every penny.
There are many other realms where the TOS is simply: use the thing, have fun with it, if you want to tell us about yourself, press this button/fill in this card. For sure, consumers 'never read the TOS', because - hopefully - the device is now set up, everything works, it is time to rock ..
For sure, tech can be used against the user. But it can also work for the user, too.
In either case, if I'm presented with pages upon pages of small font #888888 text, I defensively assume these is something nefarious hidden there (e.g. "we don't share any of your data with anyone except our 3rd party affiliates, marketing partners, your nosy relatives, people who claim to be law enforcement, anyone who wants to connect to our open s3 buckets, etc.")
I would hope there could at least be standardized agreements developed so that I could decide which I'm okay with or not and have enough companies using them to make it worth the effort to read once. I'm thinking of various flavors of FOSS or CC licenses as an idea template.
On android devices one (at least on my Huawai)(to the degree that I trust the Settings) can regulate whether an app has connectivity. I block 90% of my apps completely (e.g. workout apps, or an offline Chess app)
> my Huawai
Hmmm.
I am getting increasingly annoyed by the fact that buying anything is becoming a minefield: you have to actively scan for attempts to screw you over, and every company out there will actively try to screw you over. This goes on all over the place: think airplane ticket pricing (with all the "fees" added later), buying rental car insurance, extended warranties, security systems that suddenly enable a secret microphone, and headphones that report everything you do. There seems to be no penalty: if a company is caught doing that, they don't suffer much. They should.
Not only that, but they keep repopulating the minefield with new mines after you've spent considerable time clearing them. (Google, I really don't want you to use wifi to "improve" location precision and silently re-enabling the setting after a system update isn't going to change my mind.)
One way or another, this has to stop.
(I own the QC35 ver. 1)
[1] https://www.reddit.com/r/bose/comments/690592/bose_connect_a...
In 2011, Bose donated a majority of the company's non-voting shares to MIT on the condition that the shares never be sold. Because these shares are non-voting, MIT does not participate in operations or governance of Bose Corporation.
What the heck is the point of owning shares if you can't sell them and you can't influence the direction of the company? That sounds like an accountant's joke.
(Presumably the benefit comes from the fact that Bose Corporation pays dividends, but nothing stops the other shareholders from deciding to cut or stop dividend payments. MIT certainly has no way to stop them.)
The reason to sell a stock is because you believe the assets you have tied up in the stock would be better elsewhere.
If you view stock ownership as gambling, and dislike gambling, then don't own them. Others view them as owning shares in productive companies and a worthwhile asset for that reason.
Give me hardware interface to control the functions.
The Bose app is relatively simple as headphone apps go. Nuro and Even offer headphones with custom DSP profiles to match your hearing and the Audeze Mobius has spatial audio with motion tracking. It's simply not possible to implement features like that without some kind of companion app.
When I set up my QC35 II, I couldn't get it to pair, so I reluctantly downloaded the app. I got my headphones set up and noticed the other features, which I thought could be useful, but uninstalled the app anyway, because the amount of times I would change these settings didn't outweigh having another app on my phone that could be collecting data.
I hate that I was correct in uninstalling the software due to privacy concerns, and only reinforces my distrust of hardware and software vendors.
People have multiple devices (eg tablet and phone) which means they'd easily get into such a state.
I imagine they have to keep the most of backwards compatibility for their internal purposes as well (or at least their developers' sanity :)).
I am pretty sure having open APIs (that evolve) would still be more appreciated than not.
Losing the 0.01% of people who care about their privacy is no incentive for manufacturers to change their shady practices.
It would be nice to have some kind of privacy certification, then consumers could have an easy way of knowing the product they're buying respects their privacy.
It's a sad state of affairs that this would be needed to buy a set of headphones.
the mobius is different though but only slightly, all the sound modes etc are switchable on the device its only the head tracking setup that really needs the app
(by the way im not complaining, anyone with my spotify username can know what ive been listening to and it doesnt bother me one bit)
I can understand why the mechanism for firmware updates exists, but this constant updating of every single thing is insane. Bluetooth headphones aren't even exposed/connected to the internet.
But they also realize that intention is hard to codify in law, and when their concerns about an overly non-specific and broad legislation are dismissed with "well obviously the GDPR intends this and not that, it's such a straightforward legislation to read, anyone can understand it," it's easy to become a "hater" - because they realize that there is a lot of latitude in interpreting the law.
It would be more constructive to try to understand the position of people you disagree with, instead of labeling them as "haters" - just because someone is critical of the GDPR doesn't mean they don't value privacy.
That said, these two actions do not require to collect users data..so they should stop doing that without users’ consent
"Tech" companies? Nope.
Mind you, I would never, ever buy a Bose product, or install their app if I got one, so this is kind of academic for me.