De-anonymizing Apple UDIDs with OpenFeint
corte.si
corte.si
1. OpenFeint needs to lock down their DB
2. Phones are great for spying on people
It's simply wrong to authenticate people based solely on UDID anyways - what if the same user have one iPhone 3GS, one iPhone 4, and an iPad 2? In that case you'd need another authentication mechanism to make sure the three devices belong to the same user. The UDID is good only for telling the devices apart. So if you gave me Jane's iPad's UDID, I shouldn't really do anything unless I've made sure you're Jane in the first place.
Now, I had Fruit Ninja installed, and I had signed up for openFient.. and approved the facebook connect.
Imagine my surprise when a day later - my friend installed Fruit Ninja - so not only did it log me in, it also published to my facebook wall as me. Ended up revoking permissions - something which I should have done, but forgot to do so.
However, the real issue is whether your phone can share such information _without your explicit permission_. This is _not possible on the Android_.
http://stackoverflow.com/questions/2322234/how-to-find-seria...
You need to have android.permission.READ_PHONE_STATE permissions in order to get the unique identifier, hence users, before installing an application, will be able to determine whether their particular application is capable of doing so.
Android needs a system-wide setting that simply returns a null ID (or app+hardware specific ID, so it's useless for tracking) to all apps, regardless of specific app permissions.
----- SNIP -------
Phone calls
read phone state and identity
Allows the application to access the phone features of the device. An application with this permission can determine the phone number and serial number of this phone, whether a call is active, the number that call is connected to and the like.
----- SNIP -------
But those should be two separate permissions. One for checking if the user is on a call and a different one for reading the UDID, IMSI or IMEI.
I don't need or want users' other personal details, muting audio on a call is just what good apps do. I hate how shady my app looks on the market when it's listed as requesting permission to get a user's IMEI and subscriber info.
http://android-developers.blogspot.com/2011/03/identifying-a...
Register in Plus+ game 1, then open Plus+ game 2 and it promptly recognizes your account.
Appalling.
But it also says "Never store user information based solely on the UDID. Always use a combination of UDID and application-specific user ID."