Apple in Minefield of Privacy
2014-10-21
Last year, the “Prism Project” of the U.S. National Security Agency revealed by Edward Snowden called for the global attention to the Internet safety.
On July 11, Chinas official TV station CCTV questioned Apples collection of users positions, which might damage their privacy. According to CCTVs description, Apple recorded the users positions and moving tracks in the unencrypted data pool.
Actually, there have been several reports about Apples collection of userspositions that resulted in their privacy disclosure by both Chinese and foreign media. However, Apple rarely responded to these complaints.
This time, Apple gave out its explanation quickly. In face of CCTVs questions, Apple says that it gives users clear and easy-to-understand tips and choices so that they can keep their own information from being disclosed and get the positioning service through “safe and reliable” data pool. It also claims that it has no connections with any gov- ernmental departments of any countries in the world to invade other peoples privacy.
In the age of mobile Internet, many services are based on the positioning service. When users provide their own positions to get access to the quality services, they have to endure the risk of disclosing their own privacy. An expert says that the Chinese government should set up and improve the relevant laws against the privacy disclosure and provide detailed rules for the user of individual information.
The Second “Privacy Problem”
As reported by the CCTV, in the menu of system service under the positioning service of iPhone, a function called “regular destinations” is activated in the default state. This function not only records the names of places users usually go to, but also the time and duration the users stay there.
Wang Jiajie, an engineer with China Information Security Assessment Center, made an on-the-spot demonstration of this function. He points out that Apples iOS has a catalog that is hidden deeply, in which there is a data-pool file bearing the name “encryption”. The file collects users positions and their temporal and spatial movement tracks. Whats more surprising is that the accuracy of the recorded information that is pitched the 0.000001-percent level. Meanwhile, it also reviews the trustworthiness of the data. The file is unencrypted but hidden in a place in the form of plaintext.
Each location data links to the information of an address in the world, and the backstage file can still record the position information even if the users turn off this function. Therefore, the file in iOS is thought to have damaged users privacy.endprint
Actually, this is not the first time that Apple was questioned about secretly recording users position information.
Two security researchers in the UK found that both iPad and iPhone have such a file with the function of tracking users positions even if the service is turned off. Meanwhile, the file is not encryptd.
In 2011, 27.6 thousand users in South Korea filed a lawsuit against Apple, claiming that it used the wireless network around the mobile phones to collect users position information. Later, the South Korean court fined Apple of 3 million Korean won since it violated the Law of Protecting the Position Information.
Response from Apple
After report of the CCTV, Apple made a quick response.
It defends itself by saying that Apples own business does not rely on the collection of substantial users information. As for the existence of the file, Apple explains that it might take several minutes to use the GPS satellite data to position the mobile phone. In comparison, it only takes seconds to position the iPhone through the preserved WiFi hotspot and the signal sending beam.
Apple also denies that the “positioning service” is turned on in the default state. “Apple never allows any applications to receive the information of the devices position without letting the users know and getting their approval. There will be a warning for users, which is mandatory and cannot be covered or hidden.”
As for the rationale of “regular destinations”, Apple explains that the related information is only stored in the users own devices after being “encrypted”. “It will not be copied into iTunes or iCloud so that Apple has no way to know the ‘regular destinations of the users. We also encrypt the caches with users password to keep the information from being accessed by others.”
Positioning Service as a DoubleEdged Sword
As for the possible breach into users privacy by Apple, the industry holds different opinions.
“Getting users information is not definitely related to the invasion of privacy. In most cases, a lot of APPs, such as Baidu Map and Dazhong Review, also grab the geological positions of users and other information. Thats because these APPs can only work with the information. Whether it is invasion of privacy or not depends on whether the users submit their information voluntarily and knowingly,” says Lin Hua, director of legal affairs with Hujiang. net.endprint
Actually, many services in the age of mobile Internet are based on the positioning service. Most of the APPs will ask the users whether they want to submit the information about their geographical locations.
However, a big problem in this pattern is that the massive use of APPs renders users unable to manage their own privacy efficiently. In addition, some APPs misuse this pattern to purposely guide the users into disclosing their privacy. And worst of all, users usually do not have the ability to detect and stop the disclosure in time.
“In the future, many APPs are based on the cloud service. Therefore, it is possible for the users information to be revealed to others via illegal methods. Therefore, the government is advised to take some limitations in this matter for people in specific industries to prevent the disclosure of information,”says Wang Yinghui, secretary-general of China Alliance of Mobile Phones.
Lin Hua says that the law concerning individual information safety needs immediate improvement. “The Civil Law has some basic rules, which are not specifically set. China needs to set up concrete and special laws for the individual information and privacy on the Internet like the U.S. and Europe.”endprint
