Privacy is a growing concern in today’s world. Follow along with all our coverage related to privacy, security, what Apple and other companies are doing to keep your information safe, and what steps you can take to keep your information private.
Director of the Federal Bureau of Investigation James Comey expressed his concern today over Apple and Google’s decision to encrypt information stored on smartphones, the Huffington Post reports, adding that FBI officials are pushing both companies to change their policies in order to allow law enforcement officials to access data in certain instances.
“I am a huge believer in the rule of law, but I am also a believer that no one in this country is above the law,” Comey told reporters at FBI headquarters in Washington. “What concerns me about this is companies marketing something expressly to allow people to place themselves above the law.”
In the case of the iPhone maker, Apple CEO Tim Cook used the company’s privacy stance as a major marketing point on a number of occasions over the past month. Expand Expanding Close
In his letter on privacy shared last week, Apple CEO Tim Cook contrasted the business model of Apple against that of its competitors while strongly taking a shot at Google, Gmail, and Android without actually naming the company and services. The infinitely entertaining executive chairman of Google and former Apple board member Eric Schmidt was recently asked by ABC News about Cook’s open letter on the company and privacy.
In short, Schmidt, who is making the media rounds to promote his upcoming bookHow Google Works, said Cook’s description of Google and privacy is incorrect, which you would expect from the Google chairman. But his first shot at debunking Cook’s claim was sort of out of left field (okay, as you also might expect): Expand Expanding Close
Just as Apple published a new letter from Tim Cook and an update on privacy and security policies, a new report points to evidence the company has recently received new government demands for user data under the Patriot Act. GigaOM reports that language previously included in Apple’s Transparency Reports noting the company had “never received an order under Section 215 of the USA Patriot Act” has since been removed. That could signal, according to the report, Apple’s involvement with controversial National Security Agency programs that demand data from companies: Expand Expanding Close
Apple has just released Safari 7.1 to all users of OS X Mavericks following several beta releases in recent weeks. The update adds DuckDuckGo as a default search engine option, which was also just added to Apple’s mobile version of Safari alongside iOS 8. The update also includes a security improvement for Yahoo search engine users: Apple says Yahoo searches from the search field are now encrypted.
In addition, Apple notes the release improves Reader and AutoFill compatibility with websites.
Politico reports that Apple briefed a Congressional committee on the security and privacy of its products following concerns raised by the celebrity nudes story.
A week after Apple rolled out new products that track users’ health and fitness, the company dispatched its executives to Capitol Hill to address emerging privacy and security concerns […]
Bud Tribble, the company’s chief technology officer, and Afshad Mistri, its health product manager, briefed the powerful House Energy and Commerce Committee, according to three congressional sources.
Apple is clearly focusing on communicating its commitment to securing user data. Tim Cook yesterday published a letter on the company’s website addressing the issue. Apple also added a new webpage specifically focusing on the security credentials of iOS, OS X and its cloud services.
While it now appears clear that the methods used to obtain celebrity nudes from iCloud were a combination of phishing and weak security questions rather than any fundamental weakness in the service itself, Apple will be keenly aware that perceptions matter as much as, if not more than, facts.
As reported by the Wall Street Journal, Apple CEO Tim Cook has published a letter (below) on the company’s website expressing his commitment to the privacy and security of iOS and Mac users. Cook says that he will now issue annual updates on how user data is being handled, and the company will become even more transparent how its data collection tactics.
The executive also reiterated previous claims that neither he nor any part of the company has collaborated with governments to provide access to user information, noting again that Apple does not read users’ email, iMessages, and other communications. He also pointed out that there is no “profile” being created about user browsing habits or other data points that often interest advertisers.
The first clip of part two of Tim Cook’s interview with Charlie Rose has posted tonight with a segment on Apple and privacy. In the interview, Cook discussed the privacy of user data using Apple services as Apple has mentioned in the past.
We’re not reading your email, we’re not reading your iMessages. If the government laid a subpoena on us to get your iMessages, we can’t provide it. It’s encrypted and we don’t have the key.
Cook also discussed how Apple’s approach to Apple Pay, its new mobile payment system, emphasizing that Apple is in the business of selling iPhones, not user information like other companies. Cook commented strongly that he is “offended” by the practices of some other companies. The shot at Google, which Cook stated is his idea of Apple’s competition in the part one with Charlie Rose, was mentioned similarly during last week’s iPhone event. Cook also discussed earlier privacy issues involving “server backdoors” and Edward Snowden. You can view the new clip below…
A review of 1,211 apps carried out by a coalition of privacy officials across 19 countries found that 60 percent of them failed at least one basic privacy test, reports the WSJ.
The officials found that 60% of apps raised privacy concerns, based on three criteria: They did not disclose how they used personal information; they required that the user give up an excessive amount of personal data as a condition of downloading the app; and their privacy policies were rendered in type too small to be read on a phone’s screen …
Apple has updated its iOS 8 terms of use, according to The Guardian, to note that developers are not allowed to resell any information gained through the upcoming HealthKit framework. The HealthKit software was announced as part of a larger event earlier this year, but it was only with the most recent beta that Apple made note of this restriction.
The move is not unexpected, as it would be very much against Apple’s modus operandi to allow developers access to such crucial data without some restrictions on its use in place as a protection for users. Similar restrictions exist for the Touch ID API, which doesn’t allow developers to access user fingerprint data at all, let alone store it.
The private social network Path updated its iOS app today with a simpler chooser for posting content and a tabbed navigation bar for moving around the app. It’s biggest feature, though, follows a growing trend with mobile apps: Path Messaging has moved to a standalone app called Talk that’s rolling out today.
With its new Talk app, Path wants to replace SMS and Facebook as it focuses on privacy with a feature called Off the Record. While it’s not quite as ephemeral as instantly self-destructing messaging apps like Snapchat and Cyber Dust, Path promises its users that messages sent via Talk automatically erase from the social network’s servers after 24 hours from sending the message… Expand Expanding Close
In iOS 8, Wi-Fi scanning behavior has changed to use random,locally administered MAC addresses… The MAC address used for Wi-Fi scans may not always be the devices real (universal) address… Once the iOS device is done scanning it will give the real MAC ID.
This appears to be a security and privacy precaution as marketing and analytics companies routinely use this unique identifier to collect data about nearby devices scanning for WiFi networks. The New York Times published a story last year about a similar experiment at Nordstrom and several marketing companies selling data to retailers and more use the same method of picking up the MAC address from devices scanning for WiFi networks. One of those companies, Euclid Analytics, explains how it currently uses the MAC address of iPhones to help clients. While it notes “the MAC address does not disclose the device owner’s real-world identity nor any other personal data,” it also uses the data it collects to help clients “improve store layouts, determine timing for promotions and sales, measure the effects of advertising, and set staffing levels and store hours.”
These marketing companies do the same for Samsung and Android devices, which also do not currently automatically randomize the MAC address, but it looks like Apple might put an end to that with iOS 8.
CEOs from massive tech companies like Apple, AOL Facebook, Microsoft and Google recently issued an open letter to the US Senate regarding the growing concerns about internet surveillance. Normally competitors, this unusual alliance agrees that change is needed and that the version of the USA Freedom Act that recently passed through the US House of Representatives needs some work.
Yesterday we reported on new leaked docs from Edward Snowden reported by The New York Times and others that detailed secret NSA and GCHQ programs used to siphon data from popular smartphone apps on both iOS and Android. While Apple and Google have yet to respond to the reports, today one of the main developers singled out in the claims has. Rovio, maker of the popular Angry Birds game that was mentioned several times in the reports, today posted a response on its website.
The developer confirms that it in no way works with NSA, GCHQ or any other government organization to provide data about users, but it does point to third-party advertising networks as a possibility of the leaks:
The alleged surveillance may be conducted through third party advertising networks used by millions of commercial web sites and mobile applications across all industries. If advertising networks are indeed targeted, it would appear that no internet-enabled device that visits ad-enabled web sites or uses ad-enabled applications is immune to such surveillance. Rovio does not allow any third party network to use or hand over personal end-user data from Rovio’s apps.
Referring to the third-party advertising networks, Rovio CEO Mikael Hed said the company would have to “re-evaluate working with these networks if they are being used for spying purposes.”
Angry Birds wasn’t the only app specifically mentioned in the leaked docs, however. The reports claim the NSA program is capable of intercepting information ranging from location, age, and sex of users to address books, buddy lists, phone logs, geographic data and more from various mobile apps and third-party ad networks. Twitter, Google Maps, Facebook and others were also specifically mentioned in yesterday’s reports.
We mentioned back in June that iOS 7 uses location data to incorporate Google Now-style info into the Notification Center. In the latest iOS 7 betas, Apple allows users to see some of their frequently visited places in Settings. This helps the system determine how much traffic will be present when you need to head to your next destination.
With iOS 7, if BuzzFeed’s report is accurate, and nothing in the process has fundamentally change, it’s a feature that has to be enabled by users on setup (allowing the iPhone to use your location has been opt-in for years), and will now also include a user-facing interface so you can actually see what’s been recorded. And that, apparently, might scare people. Not the headlines that make it sound scary, of course, but the non-hidden, still relatively benign, still opt-in and disable-able, user facing feature.
By virtue of location services in iOS 7 always being able to be disabled by the user, the new user-facing-interface showing your location is actually a transparent move by Apple to ensure the user knows what the system is tracking. Of course, this is still an option, not a requirement. However, this feature will improve location-based services in iOS (for the users), and Apple’s data collection is anonymous.
App developers may soon be asked to tell us what data they collect and how it is used under a set of government proposals released today (via TNW).
The US government’s National Telecommunications and Information Administration today issued its first draft of what will be a mobile apps code of conduct intended to better protect consumers and their privacy. If made final, policy states that publishers must provide consumers with “short-form” notices in multiple languages informing them of how their data is being used […]
Just so that there’s no doubt about what “data” means, the government entity specifically says it includes biometrics, browser history, phone or text log, contacts, financial info, health, medical, or therapy info, location, and user files …
There is doubt, however, about how effective the proposals might prove … Expand Expanding Close
Bloomberg reports that the Berlin Regional Court in Germany has told Apple to change its policies for managing customer’s data on its website after ruling that Apple’s terms for data use go against German laws. According to a statement posted by a German consumer group Verbraucherzentrale Bundesverband (VSBV), the courts have ruled that Apple cannot request “global consent” for use of a customer’s data” without informing the user of where and how the data will be used. It will also no longer be able to use German users’ data to “promote location-based services and products” or deliver the data to third-parties for advertising purposes: Expand Expanding Close
The Federal Trade Commission released a report today that recommends how owners of mobile platforms can better inform consumers about how their data is being handled. The FTC named a number of companies in its report, including: Amazon, Apple, BlackBerry, Google, and Microsoft, as well as “application (app) developers, advertising networks and analytics companies, and app developer trade associations.”
The recommendations follow the FTC updating its online child privacy law to require parental consent before collecting data from children under the age of 13. It also came as Path agreed to pay an $800,000 settlement to the FTC forviolations of the Children’s Online Privacy Protections Act. Path posted a response to the FTC settlement on its website.
In the report, titled “Mobile Privacy Disclosures, Building Trust Through Transparency,” the FTC issued a number of recommendations. The FTC recommended that all platform owners “Provide just-in-time disclosures to consumers and obtain their affirmative express consent before allowing apps to access sensitive content like geolocation.” It recommended app developers take the same measures in addition to having “a privacy policy and make sure it is easily accessible through the app stores.” The report also suggested that companies implement a ” a one-stop “dashboard” into their operating systems so consumers can easily view how their data is being handled by specific apps.
Other recommendations the FTC asked Apple and others to implement include new icons that “depict the transmission of user data” and a “Do Not Track” option for users to easily opt out of their data being sent to third parties.
“FTC staff strongly encourages companies in the mobile ecosystem to work expeditiously to implement the recommendations in this report. Doing so likely will result in enhancing the consumer trust that is so vital to companies operating in the mobile environment. Moving forward, as the mobile landscape evolves, the FTC will continue to closely monitor developments in this space and consider additional ways it can help businesses effectively provide privacy information to consumers,” the report states.
A full list of the recommendations made by the FTC for mobile platform owners, advertising agencies, and app developers is below: Expand Expanding Close
In February, the story broke that Google and other advertising companies were bypassing iOS Safari’s privacy settings and continuing to track users without their consent. Google quickly disabled its code responsible for the tracking after a story from The Wall Street Journal published, and Apple then claimed it was “working to put a stop” to the issue.
Now, a new report fromMercury News claimed the U.S. Federal Trade Commission is considering whether to fine Google over the incident. The decision is expected in the next 30 days:
The Federal Trade Commission is deep into an investigation of Google’s actions in bypassing the default privacy settings of Apple’s (AAPL) Safari browser for Google users, according to sources familiar with ongoing negotiations between the company and the government… Within the next 30 days, the FTC could order the Mountain View search giant to pay an even larger fine in the Safari case than the penalty the Federal Communications Commission hit Google with Friday, say the sources, who spoke on condition of anonymity.
The report is referring to Google being recently fined $25,000 by the FCC after it allegedly “deliberately impeded and delayed” an investigation related to Street View cars. The heart of the Safari bypassing investigation is whether the company is violating a previous privacy agreement made with the FTC following controversy over the failed “Buzz” service. The report claimed Google could face up to $16,000 per violation per day for violating the agreement. Google said to Mercury News today it would “cooperate with any officials who have questions” and explained making its +1 compatible on mobile Safari created the issue:
Internet giant Google found itself in a middle of a potential public relations nightmare following a Wall Street Journalarticle this morning. Tentatively titled “Google’s iPhone Tracking,” the article asserts that “Google Inc. and other advertising companies have been bypassing the privacy settings of millions of people using Apple Inc.’s Web browser on their iPhones and computers” to follow iPhone users even after they explicitly set Safari’s privacy controls to disable such tracking. According to authors Julia Angwin and Jennifer Valentino-Devries, Google used “special computer code that tricks Apple’s Safari Web-browsing software into letting them monitor many users.” Google apparently disabled the problematic code after the newspaper contacted the Mountain View, Calif.-based Company.
Stanford researcher Jonathan Mayer discovered that although mobile Safari’s default setting blocks cookies from third parties and advertisers, Google and advertising companies Media Innovation Group, Vibrant Media, and Gannett PointRoll fooled mobile Safari into thinking “a person was submitting an invisible form to Google,” letting them in turn install a tracking cookie on users’ iPhones and PCs without consent.
Once a cookie installed, a Safari glitch allowed subsequent cookies to attach. Both Google and Apple issued statements following this morning’s report…
Let’s take a quick break from the hordes of Mountain Lion OSX news to talk about privacy issues within apps…again. However, this time the spotlight is on children’s apps in both Apple’s App Store and Google’s Android Marketplace.
The Federal Trade Commission released a report today (PDF) based on a survey that found apps for children do not fully disclose the types of data collected nor do they adequately educate parents about data harvesting.
The consumer protection agency scrutinized privacy policies, recommended each developer give comprehensible disclosures on how data is accrued and shared, including whether children’s data is linked to social network apps, and it even mentioned conducting a six-month review on disclosures and using enforcement if needed. The report focused on the two main app stores themselves and requested more be done to tell children and their parents about privacy concerns…