Mobile fraud detection in iOS 7
blog.siftscience.com
blog.siftscience.com
I'm not that familiar with the mechanics of fraud detection, and I wish the article had delved into why a physical device ID is necessary for it. What is the advantage of the MAC over, say, a hidden ID created randomly by the app on first launch?
There's an obvious difference in that the MAC would allow you to correlate identifiers across multiple apps (which is also a privacy weakness), but the given example apps aren't particularly likely to be used in concert.
The ability for apps to correlate across their own re-installations has fewer privacy implications than general UDID/MAC access, so perhaps Apple may allow it at some point. To achieve it, Apple could just change the documented behavior of the identifierForVendor property so that it no longer resets when all the vendor's apps are deleted. Apple's implementation could be done several ways (such as by stashing the per-device, per-vendor ID along with the App Store's Purchased Software data, or by generating it algorithmically from a hash of UDID/MAC plus vendor ID). But regardless, Apple perhaps sees app re-installs that start fresh and anonymous as a good thing.
that means if they get compromised people will know exactly where you live, where you go, etc. (of course they also just can lookup that info as well)