Live data from Hacker News

IPhones and 3G iPads log your location in an unencrypted file on the device

radar.oreilly.com

11–20 of 196 posts

Re: IPhones and 3G iPads log your location in an unencrypted file on the device

#11
post #7

I can sort of understand the outrage but I don't see the utility of it. Apps that are written for the App store don't have access to this data without the permission of the user. And the only way an app would be allowed access to a file outside the sandbox is if its jailbroken. I'm not familiar with the in and outs of iOS LocationManager but it generally gives you the immediate coordinates at the time you request and…

Maybe because of things like this?

>A US Department of Justice test of the CelleBrite UFED used by Michigan police found the device could grab all of the photos and video off of an iPhone within one-and-a-half minutes. The device works with 3000 different phone models and can even defeat password protections.

>"Complete extraction of existing, hidden, and deleted phone data, including call history, text messages, contacts, images, and geotags," a CelleBrite brochure explains regarding the device's capabilities. "The Physical Analyzer allows visualization of both existing and deleted locations on Google Earth. In addition, location information from GPS devices and image geotags can be mapped on Google Maps."

Re: IPhones and 3G iPads log your location in an unencrypted file on the device

#12
post #7

I can sort of understand the outrage but I don't see the utility of it. Apps that are written for the App store don't have access to this data without the permission of the user. And the only way an app would be allowed access to a file outside the sandbox is if its jailbroken. I'm not familiar with the in and outs of iOS LocationManager but it generally gives you the immediate coordinates at the time you request and…

They are collecting private information about a person and make them somehow accessible.

I'll give you an example: now your technologically savvy and pathological jealous partner can open that file on your phone while you are sleeping and check where have you been in the past months, day by day.

Iphone users should be aware of that possibility.

EDIT: Actually, now that I looked at the software presented here, it doesn't even require access to the phone, just to the computer. Your partner can do this while you are at work.

Re: IPhones and 3G iPads log your location in an unencrypted file on the device

#13
post #9
post #7

I can sort of understand the outrage but I don't see the utility of it. Apps that are written for the App store don't have access to this data without the permission of the user. And the only way an app would be allowed access to a file outside the sandbox is if its jailbroken. I'm not familiar with the in and outs of iOS LocationManager but it generally gives you the immediate coordinates at the time you request and…

What is QoS? I agree that it's not a security risk from an app store perspective but I'd still prefer not to be tracked.

Quality of service. Like when the iPhone 3G first came out you could only buy it in areas where 3G service was available. AFAIK, most carriers already do this on all their handsets but their data is restricted to just a few days to a a few months.

Re: IPhones and 3G iPads log your location in an unencrypted file on the device

#14
post #7

I can sort of understand the outrage but I don't see the utility of it. Apps that are written for the App store don't have access to this data without the permission of the user. And the only way an app would be allowed access to a file outside the sandbox is if its jailbroken. I'm not familiar with the in and outs of iOS LocationManager but it generally gives you the immediate coordinates at the time you request and…

Since the backups are unencrypted it would be trivial to steal the data exploiting a Flash hole or worst case an email virus.

Re: IPhones and 3G iPads log your location in an unencrypted file on the device

#15
Whether or not this is true, Apple should add something like File Vault to iOS. Encrypting your backups is redundant if you're already encrypting your whole home directory, but none of that matters if they have access to your unencrypted phone. Check out the police downloader devices the ACLU is investigating: http://www.aclumich.org/issues/privacy-and-technology/2011-0...

Re: IPhones and 3G iPads log your location in an unencrypted file on the device

#16
post #6

The simple solution is select encrypt backups in your iTunes options. If my computer or phone got stolen, I'd have more important things to worry about than whether the thief can find a list of locations I've been. It's fun/interesting to see it mapped out though.

You may not worry about this, but others might (and I can think of scenarios where this would be a very bad thing), and it certainly isn't apparent to most people that if your phone gets stolen, the thief has access to your location history.

Re: IPhones and 3G iPads log your location in an unencrypted file on the device

#18
post #7

I can sort of understand the outrage but I don't see the utility of it. Apps that are written for the App store don't have access to this data without the permission of the user. And the only way an app would be allowed access to a file outside the sandbox is if its jailbroken. I'm not familiar with the in and outs of iOS LocationManager but it generally gives you the immediate coordinates at the time you request and…

They are collecting private information about a person and make them somehow accessible. I'll give you an example: now your technologically savvy and pathological jealous partner can open that file on your phone while you are sleeping and check where have you been in the past months, day by day. Iphone users should be aware of that possibility. EDIT: Actually, now that I looked at the software presented here, it does…

The iphone doesn't have a file browser and apps are sandboxed. So how they would get access to this file without jailbreaking or the backup file is a much better case.

Besides, everyone knows mobile me is a jealous stalkers best friend. And it doesn't even require tech savvy, just access to the iPhone to activate the service is enough.

Re: IPhones and 3G iPads log your location in an unencrypted file on the device

#19
It might not be directly related but there was a news story on CNET [1] yesterday about cops in Michigan using a device from Cellebrite to download information from phones of people they stopped for violations that includes contacts, phone logs, messages, photographs and location history.

Does Apple's decision of having such information stored on the phone unencrypted make it easy for such devices? The device claims to subvert phone passwords though.

[1]http://news.cnet.com/8301-17938_105-20055431-1.html

Re: IPhones and 3G iPads log your location in an unencrypted file on the device

#20
post #7

I can sort of understand the outrage but I don't see the utility of it. Apps that are written for the App store don't have access to this data without the permission of the user. And the only way an app would be allowed access to a file outside the sandbox is if its jailbroken. I'm not familiar with the in and outs of iOS LocationManager but it generally gives you the immediate coordinates at the time you request and…

Maybe because of things like this? >A US Department of Justice test of the CelleBrite UFED used by Michigan police found the device could grab all of the photos and video off of an iPhone within one-and-a-half minutes. The device works with 3000 different phone models and can even defeat password protections. >"Complete extraction of existing, hidden, and deleted phone data, including call history, text messages, con…

Do you have references for those claims?
Post reply on HN