Apple iPhone location tracking has been no secret, researcher claims

By John Cox, Network World |  Security, iPhone, privacy Add a new comment

A computer forensics expert says the iPhone location tracking revelation "misrepresents" Apple, isn't a secret and that he published information about it months ago.

The claims are made in a long blog post by Alex Levinson, senior engineer for Katana Forensics, which develops Lantern, an iOS forensic analysis application. Levinson's post is a response to a presentation this week by Alasdair Allan and Peter Wardman at the O'Reilly Where 2.0 conference.

BACKGROUND: iPhones secretly stashing history of your location

As reported yesterday, the two programmers presented details of an iOS 4.0 database file, usually unencrypted, created on the iPhone and then synced to a user's Mac. This file contains thousands of time-stamped latitude and longitude pairings, apparently based on cell tower triangulation calculations. The data is a very detailed track of where the iPhone (or iPad or iPod Touch) has been. The programmers created an open source application, called iPhone Tracker, that plots the data on a map, so the user can see the track of the device's locations.

In his own blog post, Wardman notes and links to a comment by another forensics researcher that this "consolidated.db" file will be familiar to forensics researchers, that is, to people like Levinson. But it was clearly new to Allan and Wardman, who were startled at how much location data the file contained. Wardman even acknowledged another attempt in the fall of 2010, by a French writer, to popularize a wider awareness of this iPhone data file.

Levinson argues that Apple is being "completely misrepresented" by the two men, and that the file is neither new nor secret. Levinson says he discovered and wrote about it in a research paper and book months ago.

IOS UPDATE: Version 4.3.2 addresses FaceTime, 3G shortcomings

Levinson baldly asserts that "Apple is not collecting this data." His disagreement with Allan and Wardman may be a matter of differing definitions. The two programmers assert the location data collection on the iOS device is "intentional," which seems hard to deny given the fact that all agree there is a database file that stores a great deal of exactly this kind of data, and, as Allan and Wardman point out, the file is preserved across multiple backups.

Levinson seems to define "intentional data collection" as "Apple pulls this information from your personal device over a network connection into its own servers." He says there's no evidence this is happening. Allan and Wardman say the same thing: no evidence.

Levinson expands on why this data is being collected at all. "Built-In applications such as Maps and Camera use this geolocational data to operate," he writes. "Apple provides an API for access to location awareness called Core Location." He quotes from Apple's description of this software library: "... You use the classes and protocols in this framework to configure and schedule the delivery of location and heading events. You can also use it to define geographic regions and monitor when the user crosses the boundaries of those regions."

Contrary to Allan and Wardman, Levinson says this file existed before iOS 4.0: it simply had a different name, and it was hard to access even for forensics specialists. What changed in version 4.0 was that Apple allowed programmers to do some limited multitasking in iOS.

With iOS 4.0, Levinson says, "Apps now have to use Apple's API to operate in the background. ... Because of these new APIs and the sandbox design of 3rd party applications, Apple had to move access to this [location] data."

"Users still have to approve location access to any application and have the ability to instantly turn off location services to applications inside the Settings menu on their device," he points out. But behind the scenes, the actual logging of the data continues, even though a given application may be barred from using it.


Originally published on Network World |  Click here to read the original story.

ITworld LIVE

SecurityWhite Papers & Webcasts

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

White Paper

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Webcast On Demand

Distributed Database Security with Real-time Monitoring

View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Sponsor: IBM

See more White Papers | Webcasts

Ask a question

Ask a Question