iOS privacy concerns were raised last week when security researchers appeared to demonstrate that iPhones send the same analytics data to Apple whether you grant or decline permission.
The same researchers have now demonstrated that Apple can – despite assurances to the contrary – link this data back to individual users, as the same ID is used as that for iCloud accounts …
Background
When you first set up a new Apple device, you are asked whether or not you would like to share analytics data with Apple.
Help Apple improve its products and services by automatically sending daily diagnostic and usage data. Data may include location information.
You can agree to this or decline, but Tommy Mysk discovered that exactly the same analytics data appears to be sent to Apple whether or not you consent.
The App Store app was sending real-time data on your app searches, the ads you’d seen, how you found the apps you viewed, and even how long you spent looking at an app’s page. Gizmodo points out that even this data can be sensitive – for example, searching for apps related to LGBTQIA+ issues, or abortion.
The site suggested that Mysk check out other stock Apple apps, and this revealed that the same was true of Apple Music, Apple TV, Books, and Stocks. For example, the Stocks app shared with Apple your watched stocks, as well as the names of other stocks you searched for or viewed – together with the news articles you read in the app.
A class action lawsuit has now been filed over this.
Apple promises analytics data is anonymous
Even if you agree to Apple collecting analytics data from your devices, the company promises that all data is anonymous.
None of the collected information identifies you personally. Personal data is either not logged at all, is subject to privacy preserving techniques such as differential privacy, or is removed from any reports before they’re sent to Apple.
The company goes on to indicate that it may use your Apple ID to correlate analytics data from all of the devices on which you granted consent, but again says that you cannot be identified.
If you agree to send Analytics information to Apple from multiple devices that use the same iCloud account, we may correlate some usage data about Apple apps across those devices by syncing using end-to-end encryption. We do this in a manner that does not identify you to Apple.
You can see these assurances on your iPhone:
- Open the Settings app
- Select Privacy & Security
- Scroll all the way down to tap Analytics & Improvements
- Tap About Analytics & Privacy in the opening paragraph
iOS privacy concerns deepen
However, Mysk appears to demonstrate that this assurance of anonymity is false, by capturing the data sent to Apple, and comparing it to that used to identify an iCloud user by their Apple ID.
Apple’s analytics data include an ID called “dsId”. We were able to verify that “dsId” is the “Directory Services Identifier”, an ID that uniquely identifies an iCloud account. Meaning, Apple’s analytics can personally identify you […]
The analytics data that the App Store sends to Apple always contain an ID called “dsId”. We weren’t sure if this was the same as the DSID, the ID that uniquely identifies an iCloud account. We confirm that they’re the same ID.
You can see this in the video below.
We’ve reached out to Apple and will update with any response.
9to5Mac’s Take
Top comment by jgibson2400
This goes beyond their deceptive behavior, peddling the myth that first-party tracking is not tracking.
I don't disagree with Ben's take that Hanlon’s Razor may apply here if this is relatively new that all analytics is being sent to Apple. It could be a bug or error that led to the permissions dialog to not operate properly.
However, the personally identifiable information being part of the data collected - I have a hard time seeing how that could be an accident. That is what I'll be looking forward to hearing an explanation about.
It's now been a while since this was made know and has picked up quite a bit of press. There was a lengthy segment about it on MacBreak Weekly last Tuesday and a point they made then and still applies now is that Apple's silence on this makes me think they don't have a good explanation for this.
As the old saying has it, “Never ascribe to malice that which can be adequately explained by incompetence.” I’m pretty confident that Hanlon’s Razor applies here, and that the reason Apple’s assurances appear to be false is down to error rather than a deliberate intent to deceive. The company simply has too much to lose and too little to gain by any nefarious behavior of this kind.
However, as incompetence goes, this does seem pretty high up the scale. Privacy has become a huge part of Apple’s marketing message, so to fail to protect privacy in not one but two major ways is a very big deal.
Apple needs to fix this, and fix it fast.
Photo: Guillaume Bourdages/Unsplash
FTC: We use income earning auto affiliate links. More.
Comments