How Apple tracks your location without consent, and why it matters
arstechnica.com
arstechnica.com
Yes, the file should not be in the clear (it probably shouldn't exist in its current uncapped form), but can we stick to the facts, please. When we know something is being sent to Apple, we can turn on the hate.
>Yes, the file should not be in the clear
No, that file should not exist at all.
>When we know something is being sent to Apple, we can turn on the hate.
So it doesn't matter that they're collecting the data to begin with? At all? I'd prefer to be asked for permission, not for forgiveness after the fact. Only what they decide to do with it matters? Even though they've left it lying around for a year in a format you admit was inadequate?
I'm not keen on the file and will take steps to nuke it, since I jailbreak. I just thing the the level of anger is premature, until we know why the file exists (eg does it give me a better experience) or we know Apple or Google are taking the data off my phone.
This is an interesting distinction, that I don't really know where I stand. _They_ wrote the software, but it runs on a device _you_ choose to own and operate.
Allow me to as a few hypothetical questions, that I don't want to imply relate to this situation, but instead challenge some notions of who the actor is in their context: If I get a virus that encrypts my files and demands ransom, did I do it to myself? Do I run my website, or do I tell my hosting provider how to run it? If I have a device that uses TPM to make me completely unable to change, modify or understand what the code on it does, am I the one performing the actions of the software or is the writer? If I compute 2+2 serverside vs in javascript clientside, does that change who is doing the adding? If it is the owner of the device is the actor, what if the software is (unbeknownst to the user) stealing credit card numbers from the POS terminal it is installed on. Who is legally responsible then?
Software operates on its own, and can do so simultaneously for more than one party, with potentially conflicting interests. I think our shuffle to the cloud is going to run into some complex ownership, responsibility, liability and transparency questions soon, I'm interested to see how it all shakes out.
It's not like anyone can get access to it without breaking into your computer and it's not a real time feed. On top of the fact that it's only recording the gps location of the cell tower you're connected to (supposedly) it seems about as much of a security issue as my 4square feed.
edit: just looked at the article and the image at the top. Ha.
Yes in your instance, evaluated from an individual perspective, it seems absurd to worry about some imagined nefarious types breaking into your computer to get data like this.
But analysing the implications from an individual perspective is akin to forgoing fuzz testing on a web app because you'd never type all those sorts of inputs in as a normal user.
These things should always be analysed from a societal perspective. Having this type of data unencrypted means the father going through a child custody case may find all his movements lifted by a private investigator, the local politician who frequents a red light district may be at even greater risk of blackmail, and the small-town activist may find themselves harassed in new and interesting ways by local police of dubious moral character.
When presented with plausible scenarios like this there are certainly people who would still shrug and say, "I still don't care". That's fine - they're just not the people you'd trust to debate these issues, just like you wouldn't trust them debating internal security issues in a corporate environment.
However it appears that a certain segment of the community only get as far as analysing the immediate, personal impact of said security / privacy issues before giving the thumbs up. To them, there is no value in discussing / considering the wider social implications, because they don't actually care.
Perhaps that tendency should be called the narcissistic defect of security / privacy analysis.
Some number of people will lose their phone and their ex-spouse will find it and blackmail them with their location data (but not any other data on the phone). I have tabulated the total damage to society caused by this problem and arrived at a total of X. I have also tabulated the total cost of fixing this problem and arrived at a total of Y. Which is bigger, X or Y?
This narcissistic / short-term mindset is unhealthy, and is manifested in discussions around security ("I'm boring, who wants to hack me?") / privacy ("I'm boring, who's interested in me?") / liberty ("I have nothing to hide!") / environment (tragedy of the commons).
Someone working up a societal cost calculation as you outline clearly does not suffer from the narcissistic defect of security / privacy analysis that obviously rankles me. As long as people take a broader view it's perfectly reasonable to disagree on the importance / severity of a particular security / privacy breach.
In this particular instance the cost of modifying iOS to encrypt consolidated.db, store less data points, or allow users to easily opt out would be negligible.
If it was a little Silicon Valley startup they'd potentially go down in flames as HNers howled at them for taking such an amateur and reckless approach to users personal data. It'd certainly be a software defect that would quickly be patched by any little software house.
By storing a user's data in an easily-accessible, unencrypted way the barriers are low enough that private investigators, stalkers, and other unsavory types have a similar level of access to someone's data, but with none of the legal hoops and hassles.
Look, it's so easy to conceive of situations where someone's well-being is seriously impacted by having this location data stored so sloppily that it's almost not worth arguing about. Almost! ;)
What does bother me, though, is how easy this data is to get to.
http://www.geek.com/articles/news/michigan-police-can-scan-a...
...where the Michagan State Police believe that your cell phone data is searchable without a warrant, something like your cell phone storing your locations does matter. I'm a bit surprised to see this being hand-waved away by many of the commenters.
Also a point to note is the device these are on (iPhones and iPads) is making them accessible to these, so saying "without consent" seems like the wrong word. The device will have that information by default and nature of it being the middle layer.
Why Apple is putting it in an unencrypted format is a different story altogether.
I believe the article mentioned that the data comes purely
from triangulating your position with what cell towers you
are connected to.
Correct. Wi-fi triangulation data is cached in a different file (which is also stored in your backups). The consent related to location services seems to be
only related to the GPS data.
No, Location Services includes everything: Cell tower triangulation, Wi-Fi triangulation, and GPS.Let's explore the 4 scenarios:
Cell Off, GPS Off: Nothing to log.
Cell On, GPS Off: Phone knows what towers it can see, but can't set the location.
Cell Off, GPS On: Phone knows where it is, but can't see towers.
Cell On, GPS On: Phone can see towers, and knows location. Logs this data.