funsec mailing list archives

Got an iPhone or 3G iPad? Apple is recording your moves


From: Paul Ferguson <fergdawgster () gmail com>
Date: Wed, 20 Apr 2011 09:31:04 -0700

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Via O'Reilly Radar.

[snip]

Today at Where 2.0 Pete Warden and I will announce the discovery that your
iPhone, and your 3G iPad, is regularly recording the position of your
device into a hidden file. Ever since iOS 4 arrived, your device has been
storing a long list of locations and time stamps. We're not sure why Apple
is gathering this data, but it's clearly intentional, as the database is
being restored across backups, and even device migrations.

The presence of this data on your iPhone, your iPad, and your backups has
security and privacy implications. We've contacted Apple's Product Security
team, but we haven't heard back.

What makes this issue worse is that the file is unencrypted and
unprotected, and it's on any machine you've synched with your iOS device.
It can also be easily accessed on the device itself if it falls into the
wrong hands. Anybody with access to this file knows where you've been over
the last year, since iOS 4 was released.


[snip]

More:
http://radar.oreilly.com/2011/04/apple-location-tracking.html

- - ferg

-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.5.3 (Build 5003)

wj8DBQFNrwpBq1pz9mNUZTMRAol6AJ9Bq3y1mr8JBtfB/vCLNTS1xurVQwCfWf2m
186co4yE2Ds56PtUAD+r/9M=
=Y3Ui
-----END PGP SIGNATURE-----


-- 
"Fergie", a.k.a. Paul Ferguson
 Engineering Architecture for the Internet
 fergdawgster(at)gmail.com
 ferg's tech blog: http://fergdawg.blogspot.com/

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: