Live data from Hacker News

Apple Q&A on gathering and use of location data (Apple Press Release)

apple.com

141–150 of 159 posts

Re: Apple Q&A on gathering and use of location data (Apple Press Release)

#141

Earlier quoted context omitted.

As far as I can tell, the iPhone cannot determine one's location solely from the GPS antenna. If you travel to a place where you haven't been before, location services simply won't work until you obtain internet connectivity for a few seconds. I don't know if this is because the iPhone's GPS functionality is crippled, or if it's a software limitation. I'd imagine that if you wanted to overcome this limitation, you'd…

Are you sure you've had 12 minutes with a clear view of the sky? Each GPS satellite carries the entire constellation's almanac. After downloading that (which is a 12.5 minute process), then you can download the ephemeris from each satellite, which takes 30 seconds. You need 4 satellites to get a location fix. The almanac is valid for 180 days, so you only need to wait 12 minutes once. From then on, you only need the…

> I can buy a $10 microchip that's the size of a dime that can do it. Give it electricity, wait 15 minutes, the location comes out the other side.

How do you know when the 15 minutes starts, though? Dedicated GPSs tell you things like how many satellites they have in view and how accurate their fix is, but dumbed-down devices like to pretend location is magic. I'd hope they'd at least provide the gritty details through CoreLocation so a user can buy an app if she wants to know which bench outside the train station to sit at sipping coffee while the phone orients itself.

Re: Apple Q&A on gathering and use of location data (Apple Press Release)

#142

Earlier quoted context omitted.

your need is too exotic and mainstream concerns about location/timestamp tracking on iphone are real, valid concerns.

The location/timestamp concerns are only relevant when my phone has been stolen or somebody has unrestricted access to my computer. At that point, location tracking is only one of many many terrible things that can happen to me, and frankly it's nowhere near the most terrible. And if I'm concerned about somebody tracking me, I'm going to be most concerned about the last 7 days, not the past year. If you're concerned…

[deleted]

Re: Apple Q&A on gathering and use of location data (Apple Press Release)

#143

Earlier quoted context omitted.

your need is too exotic and mainstream concerns about location/timestamp tracking on iphone are real, valid concerns.

The location/timestamp concerns are only relevant when my phone has been stolen or somebody has unrestricted access to my computer. At that point, location tracking is only one of many many terrible things that can happen to me, and frankly it's nowhere near the most terrible. And if I'm concerned about somebody tracking me, I'm going to be most concerned about the last 7 days, not the past year. If you're concerned…

[deleted]

Re: Apple Q&A on gathering and use of location data (Apple Press Release)

#144
post #134

Earlier quoted context omitted.

The location/timestamp concerns are only relevant when my phone has been stolen or somebody has unrestricted access to my computer. At that point, location tracking is only one of many many terrible things that can happen to me, and frankly it's nowhere near the most terrible. And if I'm concerned about somebody tracking me, I'm going to be most concerned about the last 7 days, not the past year. If you're concerned…

Your solution is asinine, as I have little way to protect my "cache" of goods... it's unencrypted both on the device and in the backups (though you can encrypt backups now, there might be previous computer backups of mine that have unencrypted location data, now I have to go find and excise those). Any malicious desktop tool can easily find the location cache in unencrypted backups. Modern Police Forensics tools ( ht…

I'm sorry, but my solution of "protecting your data" is "asinine"?

You also say that you have little way to protect your data, and then in the next sentence tell me how to do it.

Are you really trying to evaluate the situation, or are you more interested in attempting to criticize in any way that you can stretch words?

Re: Apple Q&A on gathering and use of location data (Apple Press Release)

#145
post #13

Sometime in the next few weeks Apple will release a free iOS software update that: - reduces the size of the crowd-sourced Wi-Fi hotspot and cell tower database cached on the iPhone, - ceases backing up this cache, and - deletes this cache entirely when Location Services is turned off. Looks reasonable to me. The only thing missing that I'd like to see is an option to opt out of the tracking data (anonymous or not).

From the transcript of the phone interview Steve et al did with All Things D:

"Jobs: If people don’t want to participate in things, they will be able to turn location services off. Once we get a bug that we found fixed, their phone will not be collecting or contributing any crowdsourced information. But nor will it be calculating location."

So it looks like you will be able to opt out completely, if you really want that (but then what's the point of even having an iPhone?).

Re: Apple Q&A on gathering and use of location data (Apple Press Release)

#146
post #11
post #7

Earlier quoted context omitted.

I understand being cynical but in this case the keyword is anonymous. The encryption is for protecting in transit like you said. In order to populate their wi-fi/location database they really don't have to send over a person's IP to the server. In fact its something they don't want I would assume as it adds absolutely no value to the data. They already know who you are and where you are don't they?

They receive your IP address because that's how IP works; otherwise they wouldn't have an address to send data back (and IP packets with a spoofed source IP are dropped immediately). They might not do anything with it, but they definitely have access to it.

Isn't most wifi NAT with DHCP? what use is a big list of ip's like 192.168.1.45? They might be able to track you from the MAC address maybe?

Re: Apple Q&A on gathering and use of location data (Apple Press Release)

#147
post #134

Earlier quoted context omitted.

Your solution is asinine, as I have little way to protect my "cache" of goods... it's unencrypted both on the device and in the backups (though you can encrypt backups now, there might be previous computer backups of mine that have unencrypted location data, now I have to go find and excise those). Any malicious desktop tool can easily find the location cache in unencrypted backups. Modern Police Forensics tools ( ht…

I'm sorry, but my solution of "protecting your data" is "asinine"? You also say that you have little way to protect your data, and then in the next sentence tell me how to do it. Are you really trying to evaluate the situation, or are you more interested in attempting to criticize in any way that you can stretch words?

As of right now, anyone with an iPhone can have their localization data ripped from their device in less than 5 minutes via cellebrite. It could be a coworker, police office, or immigration official.

How is that secured?

Re: Apple Q&A on gathering and use of location data (Apple Press Release)

#148
post #147

Earlier quoted context omitted.

I'm sorry, but my solution of "protecting your data" is "asinine"? You also say that you have little way to protect your data, and then in the next sentence tell me how to do it. Are you really trying to evaluate the situation, or are you more interested in attempting to criticize in any way that you can stretch words?

As of right now, anyone with an iPhone can have their localization data ripped from their device in less than 5 minutes via cellebrite. It could be a coworker, police office, or immigration official. How is that secured?

You need more than 5 minutes, you also need access to the computer associated with the phone: http://www.cellebrite.com/images/stories/support%20files/App...

Re: Apple Q&A on gathering and use of location data (Apple Press Release)

#149
post #13

Sometime in the next few weeks Apple will release a free iOS software update that: - reduces the size of the crowd-sourced Wi-Fi hotspot and cell tower database cached on the iPhone, - ceases backing up this cache, and - deletes this cache entirely when Location Services is turned off. Looks reasonable to me. The only thing missing that I'd like to see is an option to opt out of the tracking data (anonymous or not).

I'm ok with the tradeoff, except it would have been nice if they also encrypted even the smaller cache file on the device.

Other than that, I think this is a good rational response to the situation.

Re: Apple Q&A on gathering and use of location data (Apple Press Release)

#150

The iPhone is not logging your location. Rather, it’s maintaining a database of Wi-Fi hotspots and cell towers around your current location, some of which may be located more than one hundred miles away from your iPhone, to help your iPhone rapidly and accurately calculate its location when requested Can Apple locate me based on my geo-tagged Wi-Fi hotspot and cell tower data? No. This data is sent to Apple in an ano…

> "The "bug" here is getting caught." Furthermore Apple implies that they uncovered the but themselves. The reason the iPhone stores so much data is a bug we uncovered and plan to fix shortly (see Software Update section below). We don’t think the iPhone needs to store more than seven days of this data. Again, Apple's use of language is interesting. The phrase, "the iPhone needs to store" is based on functional crite…

I found the language interesting too. It's subtle but exactly the same "you're holding it wrong", refusal to really admit wrong or truly come clean attitude that they displayed with the antenna saga.

It's a very interesting comparison as well with Google who (for example) with Buzz and the Wifi sniffing incident did complete and total mea culpas without reservation. It didn't particularly seem to help Google in those cases so it's hard to argue that Apple needs to do the same, but I do feel they would be better off with a simple and direct "sorry" and a promise to do better rather than a "oh it was just a bug, and we found it ourselves anyway, and by some definitions you're all wrong anyway so there!".

Post reply on HN