IPhones and 3G iPads log your location in an unencrypted file on the device
radar.oreilly.com
radar.oreilly.com
I suspect the slick-looking iPhoneTracker app finally made it interesting to the media.
Edit: There was a similar deal on iOS 3 but it seemed more like a bug, not a feature. Data would be purged at some unpredictable interval. I can't recall the file path and don't have an iOS 3 device handy.
Apple acknowledged that to the House of Representatives. They're gathering data about their customers, including GPS : [PDF] http://markey.house.gov/docs/applemarkeybarton7-12-10.pdf
II / C / 1 / a. : "Second, to help Apple update and maintain its database with known location information, Apple may also collect and transmit Cell Tower and Wi-Fi Access Point Information automatically. With one exception, Apple automatically collects this information only if the device’s location-based service capabilities are toggled to “On” and the customer uses an application requiring location-based infomiation. If both conditions are met, the device intermittently and anonymously collects Cell Tower and Wi-Fi Access Point Information from the cell towers and Wi-Fi access points that it can “see”, along with the device’s GPS coordinates, if available. This information is batched and then encrypted and transmitted to Apple over a Wi-Fi Internet connection every twelve hours (or later if the device does not have Wi-Fi Intemet access at that time)."
It's important to note that the above use of "anonymous" is laughable in context.
In order for that uploaded data to be useful by Apple, it needs to maintain both the lat/long and wi-fi access point ethernet addresses & signal strengths. This is pretty much a globally-unique identifier.
In location options, if you check certain options it warns you that Google will be logging wifi info and other details even while apps that access this info are not running.
The warning shown when you click "Use wireless networks" in Location settings is
"Location consent Allow Google's location service to collect anonymous location data. Collection will occur even when no applications are running."
My analysis is that this turns the phone into a mobile sensor that performs the same function as one of the Google mobiles driving around with cameras performs relating to wifi and location logging. Google probably collects the GPS coordinates and SSID of every wifi network that comes into range of a phone with this enabled. Given their recent legal troubles relating to wifi discovery, hopefully it doesn't gather more than that.
My guess is that Apple is gathering all those data in order to build their own Skyhook. It makes sense, specially when you keep in mind that Apple bough the mapping company Poly9.
Skyhook is suing them due to this.
Curious. It certainly seems to be logging way more than just when the location services icon is showing.
Maybe the news just hasn't happened yet?
EDIT: Data appears around the time I flew from NJ to Seattle -- perhaps my phone was on in-flight and connecting to MN cell towers? Seems unlikely, though, given the # of points.
I haven't dug into the raw data - is that an artifact of the iPhone Tracker application, or is the raw data already rounded by Apple to fit on a grid, with multiple locations having identical timestamps?
How much I care about this depends a lot on the granularity of the underlying data.
To make it less useful for snoops, the spatial and temporal accuracy of the data has been artificially reduced. You can only animate week-by-week even though the data is timed to the second, and if you zoom in you’ll see the points are constrained to a grid, so your exact location is not revealed. The underlying database has no such constraints, unfortunately.
* Change the precision variable on line 149 to something bigger than 100 (10000 did it for me) - this will mark points in the map with higher precision:
const float precision = 10000;
* Change the timeBucket variable on line 180 to change the date precision (the app currently gives you weekly based data, but it can go as far a data point every second). You could also just "cheat" and change the notion of weekInSeconds: const float weekInSeconds = (7*24*60*60);I'll check back often! Thanks..!
in terminal type: 'git clone https://github.com/petewarden/iPhoneTracker.git
open that new iPhoneTracker folder, and load up the xcodeproj ( iPhoneTracking.xcodeproj )
in there go to iPhoneTrackingAppDelegate.m on the left sidebar
from that look at line 179 for changing the time inbetween registering, and look at line 149 for the locational precision
with those changed, hit the play button in the top left corner and the app should build and run
First, I'll start with the WiFi data (WifiLocation table): Among the information captured is MAC, Timestamp, and Lat/Long. I have a total of 118,640 records in my table. I did a "SELECT DISTINCT MAC FROM WifiLocation", and got... 118,640 records. This tells me that it's not "tracking my every move" via Wifi location since there's a single entry for each MAC. The question might be, is it updating the Timestamp when I'm near a specific Wifi Network? My guess is no. I did the backup and analysis this morning, April 20th. Yet the last entries in my database are from April 16th. This tells me that it's not an always on tracker and that it's not updating timestamps.
Next, I looked at the CallLocation table: The same thing held true with this table. The last entry on my phone was from April 16th. Also, I have 6300 entries in my CellLocation table. I decided to start restricting the precision of the Lat/Long to see if there were duplicates that would indicate "tracking". At 5 decimal points, there were no duplicates. At 4 decimals, there were a handful that had 2 dups. At 3 decimals, there were more dups, with the most being 6. At this point I still had 5672 uniques. At 2 decimals, the most had 89 and I had 2468 uniques. At 1 it really went down, obviously, and I was down to 253 uniques. The other thing I noticed was that there was no regular timing of entries, and that when there were entries, a large number of them had the same timestamp.
So based on my analysis, this isn't a feature that enables detailed tracking of a user. It will allow you to see if a user has been in a certain location the first time, but that's the extent of it. For instance, I could see that I made a trip to Washington DC in late October of last year. But you can't really tell my movements around my home town with any amount of precision. My assumption, like others, is that Apple is using this to enable easier use of Location based services. I assume (which I'm going to test), that whenever a user enables a Location Based app (Google Maps, FourSquare), iOS updates this database with all local cell towers/wifi locations and the Latitude/Longitude. The more comprehensive the local database is, the quicker/easier it is for Location Based Services to help pinpoint a users location. Instead of waiting for GPS to spin up and get a satellite lock, it will be able to get a more accurate lock off of cell tower/wifi triangulation.
However, there's no reason why this data should not be stored by default under the OS's "Data Protection" encryption as email is by default on devices where a passcode is set:
If the data is being used to help the performance of Location Based Services, there is no need to keep years worth of data, that persists, and is backed-up every time you sync. Apple could simply keep a log of the last 4 or 5 data points.
Further, the data may not be super accurate, but that's only because the technology isn't good enough. If it were (and it will be eventually) that table would have pinpoint precise data. The precedent is being set right now. Is this ok? Personally I think this sort of behavior is unethical. Location tracking logs should be opt-in. It certainly shouldn't be hidden or a secret.
Relevant portion: http://pastebin.com/EdFJr6iU
I had 9 additional records, all Timestamped identically, from while I was using Google Maps. However, there were 112 other records where the Timestamp was updated.
So again, it seems to only update the database when you use a Location Based Service. And it does update any existing records with a current timestamp.
This database could have something to do with that.
That database isn't infinitely large, as unused location information will be removed as new location data comes in.
'Look at the video for session 115, "Using Core Location in iOS". Skip to around 13:45 for the discussion of "Course Cell Positioning" where they discuss the cache in detail.'
http://en.wikipedia.org/wiki/List_of_devices_with_Assisted_G...
If you've ever used a normal standalone GPS in one city and gotten on a plane and flown across the country and tried to use the GPS again, you'll know that it can take 5+ minutes to reacquire a fix that first time off the plane.
Wrong?
It also lists some ways that various implementations require assistance:
Assistance falls into two categories:
Information used to more quickly acquire satellites
It can supply orbital data or almanac for the GPS satellites to the GPS receiver, enabling the GPS receiver to lock to the satellites more rapidly in some cases.
The network can provide precise time.
The device captures a snapshot of the GPS signal, with approximate time, for the server to later process into a position.
Accurate, surveyed coordinates for the cell site towers allow better knowledge of local ionospheric conditions and other conditions affecting the GPS signal than the GPS receiver alone, enabling more precise calculation of position. (See also Wide Area Augmentation System and CellHunter and openBmap.)
Calculation of position by the server using information from the GPS receiver
The assistance server has a good satellite signal, and plentiful computation power, so it can compare fragmentary signals relayed to it
Assistance is described as something that’s entirely optional. Why do you think that’s not the case? I googled around for a bit and it seems as though every source I can find tells me that AGPS is just like GPS if you have no data connection.
A typical A-GPS-enabled receiver will use a data connection (Internet or other) to contact the assistance server for aGPS information. If it also has functioning autonomous GPS, it may use standalone GPS, which is sometimes slower on time to first fix, but does not depend on the network, and therefore can work beyond network range, and without incurring data usage fees.[3] Some aGPS devices do not have the option of falling back to standalone or autonomous GPS.
I've added emphasis. The last point is all I was saying.
So first, someone asked whether the iPhone triangulates position from cell towers or uses GPS. I responded that it does AGPS, and that in some ways AGPS is inferior to standalone AGPS.
You objected to this, saying that AGPS is "actual GPS" which, in fact, it is not. If by "actual GPS" you mean standalone GPS, then you are wrong. I correctly pointed out to you that AGPS is not a standard definition, but a name for one of a wide range of techniques which involve assistance from a third party in determining position. You, in fact, were incorrect.
Failing to comprehend the article from Wikipedia which, in fact, enumerates the methods by which an AGPS device may receive assistance, you asserted that AGPS only refers to the technique of optionally downloading an almanac from a network resource instead of an orbitally transmitted signal. Again, you were incorrect.
Now that I've shown that you were incorrect, you want to object to raising irrelevant points? My only point was that the device uses AGPS, and that AGPS is not standalone GPS -- that in some ways it is inferior. I showed those ways because you asked, not because the Apple implementation is encumbered by them.
It uses towers to work out how to find the GPS satellites quicker than normal, and additionally can provide some location information when no GPS is available.
Really? My Garmin device can locate itself without entailing the possibility of communicating my position to a third-party. There is no possibility that my checking my position can enable anyone else to know it as well. That's not true with AGPS.
That is one pretty significant way that standalone is superior.
Maybe.
The majority of people just want to know where they are and the quicker the better.
I think it was pretty clear that we were talking about performance – time until and precision of the first lock (which AGPS does improve), overall precision (which AGPS doesn’t improve) and so on.
My understanding is totally opposite, would you mind explaining a bit more?
You can claim "I edited it", which then weakens the evidence. Then they will look for other evidence, and try to look at everything as a whole.
Does Apple's decision of having such information stored on the phone unencrypted make it easy for such devices? The device claims to subvert phone passwords though.
Most forensics labs have multiple tools such as this, and still have issues fully collecting devices.
My understanding is that all data and files is persisted in that manner. Not sure why they're implying this file has been singled out.
The fact is, that phone companies store all that data for EVERY cell phone, and it's always available to government agencies and divorce attorneys after a subpoena.
All this does is raise the common man's awareness, and possibly provides an afternoon of fun looking at your travel history. If you want your iphone data secret, it prompts you to encrypt your backups when you first plug the phone in.
The file can be viewed with any ol' SQLite browser, and the location information is stored in the "CellLocation" table.
After using an iPhone 4 since release day, I have ~1400 entries.
if (!loadWorked) {
loadWorked = [self tryToLoadLocationDB: @"/path/to/your/consolidated.db" forDevice: @"iPhone"];
}On a more interesting note if you put '); droptable; into your file could you delete the receiving database? A whole new vector for SQL injection hacks I suspect.
Good detail on how and why it is generated.
Earlier, entities recording: cell company. Earlier, entities with access: police, cell company
Now, entities recording: cell company, Apple Now, entities with access: police, cell company, anybody who temporarily gains access to my phone, anybody who temporarily gains access to my iTunes computer
See, how the "attack surface" is dramatically bigger now?
I'm just saying keep in mind this info is also available to others without an iphone.
make print statement to print() function.
If so, this is probably a non-story. I'd be interested if it still logs if Location Services are off, too.
Such sensitive data should not be saved without the user's explicit permission if it's not needed for some purpose the user explicitly wants to use the device for.
In fact, keeping a database like this could actually give Apple LESS information about your location, as you don't have to request a new location if you already have the info of all the near ID's in your database. I'm not sure if this actually happens though.
The same, of course, can be said for any Android device and Google's A-GPS database; you have no guarantees that Google isn't logging your location whenever you're using location services.
I'm not familiar with the in and outs of iOS LocationManager but it generally gives you the immediate coordinates at the time you request and nothing more. As for why the database of locations? It's entirely possible they are using it for QoS.
As for access to device backups. If someone has unauthorized control of your desktop computer you have bigger problems.
I'll give you an example: now your technologically savvy and pathological jealous partner can open that file on your phone while you are sleeping and check where have you been in the past months, day by day.
Iphone users should be aware of that possibility.
EDIT: Actually, now that I looked at the software presented here, it doesn't even require access to the phone, just to the computer. Your partner can do this while you are at work.
If you don't trust your partner and want to rummage through his or her computer—or if you worry about the prospect of your partner rummaging through your computer—you may want to go to a couples' therapist.
Thanks, I am fine. But you should know that a number of marriages do in fact end badly in the real world and that a tool like this one can give evidence of cheating and cost a lot of money in a divorce trial. Do I need to make any more examples of why collection of private information is frequently a problem in everyday life?
To be clear, the collection of the data is only a "problem" if it exposes you as a liar. And it's not a "problem" for the person who was lied to; it's a boon. And if you weren't cheating, well, showing your call or location logs might be a way of saying, "Look, I have nothing to hide."
Privacy vs. disclosure of data is a complicated issue. It involves issues of personal autonomy as well as trust. Do you give up some autonomy because you know that people know what you're doing at any moment? Of course. But there is often a pay-off to doing so: people actually trust you.
Life is complicated, and you can't down-vote moral complexity out of life, no matter how high your karma is.
So to answer his question honestly: Yes, you are implying exactly that.
Turn the issue around: how would you feel if Apple bent over backwards to help your partner fuck other people behind your back and leave no trace?
I don't know why I'm bothering to write this, because you seem resistant to the concept of moral subtlety, but I will anyway: Studies have been done that show that morally equivalent choices can be posed in ways that lead to people using different moral heuristics for making decisions and reliably making different choices.
People move through the world and leave traces of that movement. Where should device makers stand on the continuum between recording everything and distributing it to everyone and recording nothing (and erasing everything it possibly can) and making sure that no information about a user's actions can leak out.
Do you understand that this is not a binary choice? Do you understand that there are outcomes that you and I can agree to call good or bad that can result from making a decision anywhere along this continuum? Do you understand that there is no easy solution? Do you get it?
In such an investigation, your location history could be obtained from the mobile provider. Therefore this additional data could only possibly be of use to people who have no right to it in the first place.
So to phrase it in your language; yes, Apple's highest moral obligation is preventing the collection of unnecessary data about me, and indeed to tell me what it is collecting, why, and to whom it will be disclosed. In fact, where I live, all these principles are enshrined in a law called the Data Protection Act.
In the UK and the wider EU at least, Apple could be in a considerable amount of trouble for collecting this data.
Edit x2: grammar.
You really are hung up on this "nothing to hide" deal aren't you?
Besides, everyone knows mobile me is a jealous stalkers best friend. And it doesn't even require tech savvy, just access to the iPhone to activate the service is enough.
The backups are stored on your Mac/PC, which are likely to have Flash.
I agree that it's not a security risk from an app store perspective but I'd still prefer not to be tracked.
I am switching to Tmobile because ATT makes me want to go on a rampage. Of course, now using this file, they'll be able to predict where that rampage will occur.
[1] This is according to a commenter on another blog. I'm still on 3.1 so can't verify these claims either way. But this seems to confirm it http://blog.csvance.com/?p=39#comment-109
>A US Department of Justice test of the CelleBrite UFED used by Michigan police found the device could grab all of the photos and video off of an iPhone within one-and-a-half minutes. The device works with 3000 different phone models and can even defeat password protections.
>"Complete extraction of existing, hidden, and deleted phone data, including call history, text messages, contacts, images, and geotags," a CelleBrite brochure explains regarding the device's capabilities. "The Physical Analyzer allows visualization of both existing and deleted locations on Google Earth. In addition, location information from GPS devices and image geotags can be mapped on Google Maps."
Also, collecting a 64GB i<device> over USB will take at least 24 minutes. (You don't really just want the photos, do you.) That makes for a long traffic stop.
Also, what the hell are you doing turning over your phone to police officers during traffic stops......
There are several reasons that one might turn over one's phone, all well documented in the media. The primary two are:
1) Voluntary cooperation with a request 2) Search incident to arrest
(Obligatory WTF on downvoting: I point out reasonable information and a technical challenge with doing this in the field based on personal experience as a forensic examiner, and I get downvoted?)
(I didn't downvote you)
yes, with access to a plist file from iTunes
[credit to morganpyne http://news.ycombinator.com/item?id=2465752]
http://www.tipb.com/2011/03/18/daily-tip-enable-data-protect...
And I assume Cydia will now get an app that forces them off if the os ignores the setting.
Despite the utility I got out of this, I wish we would be told about it...
Anyway, of course I'd agree it's worth fixing on Apple's part. In the meantime... hold onto your phones, I guess?
I also assume that if you put a passcode on with the 'erase after 10 incorrect attempts' setting that this would be permanently erased if they get your passcode wrong 10 times...?
I hope Apple doesn't respond to the "outrage" by no longer collecting this data. To a first order approximation, I am with Scott McNealy over in the "Privacy?! Get over it" camp:
http://www.wired.com/politics/law/news/1999/01/17538
As an aside, can real outrage even exist anymore in this age of the easy forum post or re-tweet or tumblr entry or Facebook post? And if it does, how do you identify it? And if you can identify it, what does it mean?
It's simple really, many people believe that privacy relevant data shouldn't be collected without the users consent. There is nothing at all wrong with collecting location data if the user has agreed to it, that changes if said consent is missing. Just as with sex.
Show me the person that Apple has hurt. The only people I've been reading about here taking actions are law enforcement officials, people in black helicopters, and betrayed lovers.
If either of those has sex with me without my consent, then yes. I would call that rape. Who in their right mind wouldn't?
More people should know.
Then use something like Latitude. There are options for you if you want to see this data other than having Apple collect data from all users whether they like it or not.
I guess I have some sort of perverse desire to see my karma auger into the x axis thanks to this issue, because people seem to be whiny hysterics on it. Computers log data. A phone is a computer. The history of the phone's location is conceivably useful—it's like a geospatial stack trace—and even if this data is going to the Apple mothership, I don't care as long as the data gets Tivo-ified.
Still, I don't see why this is better than an optional, third party application for this data. I also think that people should be upset at their phone keeping this data without their knowledge. You say it could be useful, but useful to whom? Advertisers, stalkers, "The Government"? I can't see how this useful to most users at all.
computers log data, A phone is a computer.
I think most people view their phone somewhat more intimately than their computer. Notice the uproar any time privacy issues like these are raised about a phone. Furthermore, tracking someone's location is just about the creepiest thing you could do for most people. It's just ripe for abuse, and as I stated earlier, I can't see much in the way of positive use.
No, the distinction is critical to most people. Apple's iPhone software records all the calls I make, the phone numbers I call and the duration. That's fine.
I'd be pretty peeved if that information was harvested by Apple Inc.
Thank you in advance.
My amusement outweighs my outrage.
But if any of you are pathetic and creepy enough to want to know where I was on any particular day, feel free to send me e-mail at edw@poseur.com and I'll let you know.
I don't mind that Apple have saved the information on the device, what I mind is that they haven't given us an option to clear the logs or to actually visualise the data directly from the phone.
http://arstechnica.com/apple/news/2010/07/apple-responds-to-...
http://technicalmusings.blogspot.com/2011/04/ios-consolidate...
If you tuink about how much information you have on your phone, if somebody has access to it or to your backups, I think your locstion history is the least of your problems. But I do agree that it should not store this information, encrypted or not...