• TalkBass has been independent since 1998. Add your voice.
    Create a free account to reply to discussions, view embedded media, and browse with fewer display ads.
    Join freeLog in
    Want zero display ads or expanded classifieds tools? Compare plans.

Apple Users, Beware: iPhones Secretly Tracking Location, Experts Warn

Invalid Link Removed

Smartphone Searches Not So Smart—Analysis
This week, reports surfaced of police in Michigan using forensic devices that can quickly scan the contents of your phone during routine traffic stops. The Michigan State Police has denied using the devices without a warrant or consent, and PM columnist Glenn Reynolds argues that such searches would be illegal. But, he says, it’s the bigger picture that’s truly worrisome: The combination of smartphones loaded with data about you and law enforcement devices that can easily extract that information means that a privacy war is looming.

As Popular Mechanics reported earlier in the week, reports have surfaced that police in Michigan are using an electronic device, the Cellebrite UFED, that can pull data off a variety of cellphones and smartphones, including Android devices, iPhones and iPads. According to Cellebrite’s website, its UFED can obtain email, Web bookmarks, Web history, SIM data, cookies, instant messages, Bluetooth devices, GPS fixes, call logs, contacts and much more from your phone.

That police are using such a device might be troubling in itself, though it’s easy to imagine legitimate law-enforcement uses for that kind of data. But what’s more troubling is that they may not be using it in the course of major investigations into drugs or terrorism where that might make sense. Instead, the letter by the American Civil Liberties Union that sparked this controversy alleges that Michigan police are using it to snoop through smartphones at random traffic stops. The Michigan State Police are now denying such use, and say they only use the devices with a warrant, or with a person’s consent. (Why would you consent? Beats me.)

Regardless of what’s actually going on in Michigan, these reports have led many people to wonder: Can that kind of random cellphone search possibly be legal?

Probably not. Traditionally, a police officer may search a person when he makes an arrest. But a traffic stop isn’t an arrest. A police officer who pulls you over for an illegal lane change can arrest you if he sees contraband—a bag of marijuana, say—in plain view, but he cannot search your car just to see what he turns up. There’s even less justification for searching a cellphone. Even with an arrest, a warrant may be required to search a closed container: Just last year, the Ohio Supreme Court held that a cellphone is analogous to a closed container and cannot be searched without a separate warrant—and that’s for a search where someone has actually been arrested for a crime, not mere snooping during a traffic stop.

Without an arrest, search requires probable cause—the officer must have some reasonable basis for believing that a crime has been committed, and that a particular search will turn up evidence relevant to that crime. It’s hard to see how cellphone data could be relevant to a traffic stop. Instead, searching cellphones looks more like a fishing expedition: Having gotten access to you with a traffic stop, officers are just looking around to see what they find. That’s explicitly forbidden by the Constitution, and with good reason. Letting government officials snoop on anyone they choose, for no particular reason, is a bad idea.

If you consent to a search, however, all bets are off. It’s hard to see why anyone would do so: If you’re a criminal, you’ve got something to hide; and if you’re not a criminal, why would you want to let the police paw through your email? And remember that when you consent to have your smartphone searched, you’re also giving up data on all your contacts, who haven’t consented. The legal ramifications to that have yet to be worked out.

This is just the beginning of a new era of privacy invasions and legal complications, particularly those surrounding your phone or other mobile device. For example, your smartphone contains a lot more information about you than your emails and the numbers in your address book. Your phone knows where you’ve been and what you’ve done. Consider the recent revelations that Apple iPhones actually maintain an internal file of the user’s locations, one that is copied to the user’s computer when the phone is synchronized to iTunes. These phones may store as much as a year’s worth of location data—data that could be snooped by law enforcement, creditors, jealous spouses, or— more troubling, and probably more likely—hackers, malware operators and stalkers.

What happens if police gain access to all this information through your phone? Courts are only beginning to grapple with this. Take the question of location tracking: One federal magistrate has held that the government must have a warrant even to obtain cellphone tracking information from a cellular carrier. The cellphone system routinely logs which cell towers contact your phone as you travel about, and that data provides a pretty good map of your whereabouts. It’s a good enough map, the court decided, that police shouldn’t be able to access it without a warrant. Likewise, the U.S. Court of Appeals in Washington, D.C., ruled that installing a GPS tracker in your car requires a warrant. However, other cases have held that putting GPS tracking devices on suspects’ cars doesn’t require a warrant—the argument is that whenever you drive your car, you’re in public view, and thus have no expectation of privacy regarding your whereabouts, so you’re not harmed by the tracking. (I feel certain, however, that if I went down to the nearest federal motor pool and installed GPS trackers on their vehicles, they’d take a different view.)

Experts have been warning of privacy threats for years, and for the most part the public has yawned. But the combination of devices that gather all sorts of information about you and law-enforcement agencies wanting to snoop on it has put us into a whole new ballgame.
 
Apple Sued Over iPhone Tracking

Two men have filed a class-action lawsuit against Apple over the location-based services provided in iOS 4. The practice puts users at a serious risk of privacy invasions and stalking, they argued.

"Apple collects the location information covertly, surreptitiously, and in violations of law," according to the lawsuit, which was filed Friday in Florida district court.

The issue of iPhone tracking made headlines last week when two researchers published a blog post that said iOS 4+ devices collect a users' location in an unencrypted file known as "consolidated.db." It's no secret that Apple collects this data to serve up location-based services, but the researchers were concerned that this information is stored in an insecure manner, and transferred to a user's PC when they sync their iOS device.

Apple has not issued an official statement on the matter, but when a user emailed Jobs about it and mentioned that his Android phone does not collect location information, Jobs reportedly responded: "Oh yes they do. We don't track anyone. The info circulating around is false."


That statement did not appease Vikram Ajjampur of Florida or William Devito of New York, who filed suit over the reports.

The duo claim that "users of Apple products have ... no way to prevent Apple from collecting this information because even if users disable the iPhone and iPad GPS components, Apple's tracking system remains fully functional."

In a test, PCMag found that turning off location services appeared to stop the collection of data, though this occured over a 45-minute period and Apple has not revealed when exactly it collects data from peoples' phones.

Ajjampur and Devito, however, who own an iPhone and 3G iPad, respectively, said Apple is collecting information about which even employers and spouses might not be aware. Users are being "personally tracked just as if by a tracking device for which a court-ordered warrant could ordinarily be required," they said.

The duo want Apple to disable this type of tracking in the next release of iOS.

Last year, Apple updated its privacy policy to say that it could "collect, use, and share precise location data, including real-time geographic location of your Apple computer or device." That prompted a congressional inquiry, and Apple said in response that it collects data "anonymously in a form that does not personally identify you and is used by Apple and our partners and licensees to provide and improve location-based products and services."

Ajjampur and Devito argued that "Apple's privacy policy contained deceptive misrepresentations that are material and are likely to and did deceive ordinary consumers ... into believing that their every move would not be tracked by Apple and then stored for future use in an Apple-designed database."

Apple should have had a "single sentence disclosure" rather than adding a line to a lengthy terms of service, they said.

Apple has "a duty not to stalk consumers. But that is exactly what Apple has done and continues to do," the lawsuit said. It's like a Trojan Horse that "delivered products to spy on plaintiffs and class members and to sell their personal information at a future date."

This is just the latest lawsuit to stem from press reports about Apple privacy-related matters.

In January, a California man filed suit, accusing Apple of producing devices that allow ad networks to track a user's app activity. A month later, another man filed a similar suit against Apple for transmitting user information to third parties without permission. And earlier this month, a Pennsylvania man filed suit against Apple for what he considered to be the "unlawful exploitation" of children (and their parents' wallets) via Cupertino's in-app purchasing policies.

Apple Sued Over iPhone Tracking | News & Opinion | PCMag.com

Invalid Link Removed

Apple: We 'must have' comprehensive user location data on you
 
Wait, people are shocked that Darth Jobs wants to know what you're up to?

Even if I were to de-Google my Android phone, what stops my cell carrier from tracking my movement? Hasn't that been available all along should someone want access to it? The US government has required that cell phones sold in the US have a GPS device in them since the '90s. If they want to find me, they'll know where I am.

How about my internet service provider? They can tell lots about me should they want to. I bet there's quite a record built up as to what websites I've been to and what changes I've made in my computer should someone become interested for some reason.

I'll bet my purchasing habits are easily accessible, all nice and legal, to interested parties thanks to my debit card.

Just a short hundred years ago, in my neck of the woods, it was a relatively simple matter to track someone's movements through simple surveillance, without them ever knowing they were being trailed and their business being noted. Welcome to the 21st century equivalent.

EDIT: Anyone noticed the banner ad for a cute-looking little mobile purchasing device at the top of this page? I wonder how many companies have access to the data that little sucker collects.
 
Android phones do the exact same thing

uhmmm....no.

there is no database file of stockpiled gps coordinates in the android system. let's be honest with ourselves. with android's open source coding, that would have been found 2 years ago when android was released and cyanogen rewrote it to make his mod. the amount of eyes that have looked over android is probably in the thousands, if not millions. that's the safety of open source. there are no secret bugs, because there are no secrets.

iphone users bought a closed-code device from a company that would sell a drowning man a life vest, and wonder why everything about them, all of their information, is for sell.
 
Android phones also tracks your movement (though to a much more limited scale: only collects the 200 most recent spots and they did tell you in their EULA) was what I was told by a friend who owns an Android phone.

This is right.

Also, Android phones are more "naturally" open to third-party, never audited applications. If Apple can catch a developer trying to submit a spy app thanks to their closed garden policy, Google doesn't step between malicious app publishers and the customers.
 
SteveJobs2.jpg


2011-04-25-humancentipad.jpg


[Invalid or Expired Link Removed]

Always read the terms and conditions!
 

Latest posts