Announcement

Collapse
No announcement yet.

Your iPhone is logging everywhere you go to a hidden file on the device

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Your iPhone is logging everywhere you go to a hidden file on the device

    If you have an iPhone with iOS 4 or higher, check this program out: http://petewarden.github.com/iPhoneTracker/

    Apple added a feature in iOS 4 to discretely log to a file your current location at given time intervals. It is stored unencrypted on your phone and on your computer. This program access it and maps it at a certain time.

    Big Brother.
    "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
    Ben Kenobi: "That means I'm doing something right. "

  • #2


    Security researchers find iPhones, 3G iPads track user location
    By Chris Foresman | Last updated 20 minutes ago

    Two security researchers have discovered that iPhones and 3G-equipped iPads regularly record and store location information to a hidden file that is backed up to iTunes and even transferred to new devices. While the information isn't necessarily accessible to remote hackers, the researchers noted that it does raise some important concerns about privacy.

    Researchers Alasdair Allan and Pete Warden announced this morning that they are presenting their findings at the Where 2.0 conference on Wednesday. "Ever since iOS 4 arrived, your device has been storing a long list of locations and time stamps," the pair noted in a post to O'Reilly Radar. "We're not sure why Apple is gathering this data, but it's clearly intentional, as the database is being restored across backups, and even device migrations."

    Warden developed software to view and analyze the database of locations stored by your iOS device, a copy of which is likely sitting unencrypted on the computer with which you sync your iPhone or iPad. The pair advised that turning on backup encryption in iTunes is an easy way to protect the information from leaking, though anyone with physical access to your iDevice could potentially access and analyze the database.

    We have contacted Apple and several security experts to get a better understanding of the privacy and security implications of Allan and Warden's findings. Keep an eye out for our in-depth analysis on the issue later today.
    "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
    Ben Kenobi: "That means I'm doing something right. "

    Comment


    • #3
      Particularly troubling because some police in America now downloading phone data at traffic stops...

      CNET is the world's leader in tech product reviews, news, prices, videos, forums, how-tos and more.


      1984 is here?
      "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
      Ben Kenobi: "That means I'm doing something right. "

      Comment


      • #4
        not for tecnophobes like me
        "The Christian way has not been tried and found wanting, it has been found to be hard and left untried" - GK Chesterton.

        "The most obvious predicition about the future is that it will be mostly like the past" - Alain de Botton

        Comment


        • #5
          Yes, 1884 is for you.
          "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
          Ben Kenobi: "That means I'm doing something right. "

          Comment


          • #6
            serious question, why are they doing this? do they think they can sell the data or use it in some other way or have the authorities asked them to collect this kind of data.
            "The Christian way has not been tried and found wanting, it has been found to be hard and left untried" - GK Chesterton.

            "The most obvious predicition about the future is that it will be mostly like the past" - Alain de Botton

            Comment


            • #7
              Apple needs to know the best places to open new stores.
              Pool Manager - Lombardi Handicappers League - An NFL Pick 'Em Pool

              https://youtu.be/HLNhPMQnWu4

              Comment


              • #8
                Originally posted by C0ckney View Post
                serious question, why are they doing this? do they think they can sell the data or use it in some other way or have the authorities asked them to collect this kind of data.
                They aren't commenting on it. Or haven't yet.

                Speculation is they may be using it as some kind of cache for location triangulation (used when no GPS signal is found). I find this unlikely.
                "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
                Ben Kenobi: "That means I'm doing something right. "

                Comment


                • #9
                  I keep my iPhone in a Faraday cage at all times, so I'm safe from these sorts of intrusions. Granted it doesn't get very good reception, but that's the price you pay to be secure and trendy at the same time.
                  <p style="font-size:1024px">HTML is disabled in signatures </p>

                  Comment


                  • #10
                    Originally posted by C0ckney View Post
                    serious question, why are they doing this? do they think they can sell the data or use it in some other way or have the authorities asked them to collect this kind of data.
                    Not sure but I do know that one of the advertisments/features/bugs for latest IOS (4.2 and greater) was ability to have free "find your Iphone, Ipad app" built into the operating system.

                    http://www.apple.com/ios/
                    "Just puttin on the foil" - Jeff Hanson

                    “In a democracy, I realize you don’t need to talk to the top leader to know how the country feels. When I go to a dictatorship, I only have to talk to one person and that’s the dictator, because he speaks for all the people.” - Jimmy Carter

                    Comment


                    • #11
                      don't have one

                      Comment


                      • #12


                        How Apple tracks your location without consent, and why it matters

                        If you haven't yet enabled encrypted backups for your iPhone or iPad, now's definitely the time to start. Two security researchers have discovered a simple way to map out where you've been almost anywhere in the world—without any hacking involved. The information comes from a location cache file found within your iPhone's backups on your Mac or PC, bringing out serious privacy concerns and opening the door for a jealous spouse, thief, or even a crafty trojan to take a detailed look at your whereabouts. And it's information that no one should have access to—not even law enforcement, barring a court order.

                        Researchers Alasdair Allan and Pete Warden revealed their findings on Wednesday ahead of their presentation at the Where 2.0 conference taking place in San Francisco. The two discovered that the iPhone or 3G iPad—anything with 3G data access, so no iPod touch—are logging location data to a file called consolidated.db with latitude and longitude coodinates and a timestamp. The data collection appears to be associated with the launch of iOS 4 last June, meaning that many users (us at Ars included) have nearly a year's worth of stalking data collected.

                        In order to drive the point home, the two developed an open source application called iPhone Tracker that lets anyone with access to your computer see where you've been. For example, my log appears to start on June 23, 2010 (one day before the launch of the iPhone 4) and shows nearly every trip I've ever taken since then and when. You can see that I seem to spend most of my time in Chicago and occasionally the suburbs, with road trips down to Indianapolis, Cincinnati, Springfield, and Wichita. I also fly to New York City and San Francisco, and I have a few dots at the Tokyo Narita airport when I traveled through there in October.

                        What's not shown is a week-long trip I took to Hong Kong in October. Why? Because I left my iPhone's cellular and data connections turned off and only used GPS with WiFi while I was there. But if I know I used GPS in Hong Kong in order to make geotagged tweets and photos, shouldn't it show up in this log file? The answer is no, and the reason behind it should scare you.
                        Court order required—or not

                        From the end-user point of view, Apple only does one kind of location tracking, and it happens via GPS. The company makes sure to notify you on your iPhone or iPad every time you use an app that will grab your GPS location so that you're always informed of when you're being tracked. However, that's not all that's going on behind the scenes. Apple also triangulates your location from cell phone towers and logs that information in order to help get a faster GPS lock (or to find your location without GPS if you're getting bad GPS signal).

                        Allan and Warden point out in their iPhone Tracker FAQ that this is indeed the method Apple is using in the consolidated.db file, and this is also the reason users might see strange iPhone Tracker dots in places they haven't been.

                        "As far as we can tell, the location is determined by triangulating against the nearest cell-phone towers. This isn’t as accurate as GPS, but presumably takes less power," they wrote. "In some cases it can get very confused and temporarily think you’re several miles from your actual location, but these tend to be intermittent glitches."

                        Users don't get to decide whether their locations are tracked via cell towers or not—unlike GPS, there is no setting that lets users turn it off, there's no explicit consent every time it happens, and there's no way to block the logging. (Nitpickers will point out that you do give your consent to iTunes when you download and install iOS 4, but this is not treated the same way as the consent given to the iPhone every time an app wants to use GPS.) So, whether or not you're using GPS, if you're using your iPhone as a cell phone, you are being tracked and logged constantly without your knowledge. This is why my trip to Hong Kong wasn't logged (because I had all cell connections turned off while GPS was on), but my stop-over in Tokyo Narita on the same trip was logged (I had turned on my phone to make a quick call, but did not use GPS).

                        Of course, the fact that this data exists somewhere is nothing new. Cell companies have been tracking this triangulation information for their own purposes for years. In the US, however, regular people cannot access that data—law enforcement must obtain a court order before they can get it for an investigation, and your jealous spouse can't get it from the wireless company at all.

                        What the cellco has on you is now basically being mirrored in a file on your iPhone or iPad without any kind of encryption, and is also being copied to your computer. (Allan and Warden say that, according to their research, no other phones log triangulated cell locations in this way, including Android phones.) And, if you leave iTunes on the default syncing settings, your iPhone backups aren't being encrypted on the computer either, making tools like iPhone Tracker possible.
                        Who has access now?

                        So your iPhone—and probably your computer—now both have a file that mirrors data that was previously limited to law enforcement, which itself was only able to obtain it from a court order. Without encrypted backups, someone who has access to your computer can see your whereabouts. "By passively logging your location without your permission, Apple have made it possible for anyone from a jealous spouse to a private investigator to get a detailed picture of your movements," the team wrote.

                        But even if you check the box to encrypt your iPhone backups on the computer, the file is still unencrypted on your iPhone, and it wouldn't be hard for someone with ill intentions to access it.

                        "Anyone with a good jailbreaking tool could get it off the phone too. And of course my forensics tools," iPhone hacker and forensics expert Jonathan Zdziarski told Ars. "In fact even the old SSH worms (which are still effective on a large number of handsets) could be modified to collect this. It's part of the Core Location cache on the phone. So, it's not a covert, evil, Big Brother secret invisible file, but Apple has been administratively lazy in their programming, which is the root cause of most data leaks on the iPhone."

                        Security expert and repeat Pwn2Own champion Charlie Miller was slightly less pessimistic about who can access the file, but agreed that it wouldn't be trivial for an experienced iPhone tinkerer.

                        "This file is only readable by root. That means that a rogue App Store app won't be able to read it. Even a bad guy who hacks into your browser won't be able to read it," Miller told Ars. However, remote hackers can make use of two separate exploits—a code execution exploit and a privilege escalation exploit—which Miller points out have been available before in the form of jailbreakme.com (a tool that allowed users to jailbreak their devices through a Web page on the Internet).

                        Although Apple makes an effort to patch security holes as they come up, the jailbreak community is constantly working on new ways to gain access to previously forbidden files—if something like Jailbreakme existed before, it could exist again.

                        "It is bad for privacy this file exists, especially when it doesn't seem to be linked to any particular feature that provides any benefit," Miller said. "[T]here is no easy way to wipe the data from it."
                        Implications for Apple

                        Zdziarski says the iPhone has actually been logging this location data for longer than a year, but it wasn't so easily accessible before the launch of iOS 4 in mid-2010.

                        "The iPhone has been keeping caches of user location data for quite some time now. iOS 4 made it a little easier to get to, but law enforcement has been using data like this since around 2009 to build evidence against criminals using the iPhone," Zdziarski told Ars. "Similar data has been cached in different files prior to iOS 4. [The cache revealed today] is a bit more aggressive and centralized, making it easier to access by normal folks."

                        Apple did not respond to our questions about how long it has been logging the location data, but it's clear that the reason the issue is coming to light now is because of this easy access. Zdziarski added that the iPhone in general "leaks like a sieve," and warned that consumers should consider the possible implications to their personal privacy with today's discovery.

                        Privacy advocates are taking things a step further by calling out Apple for abusing user trust. "Apple has some explaining to do. iPhone owners place a great deal of trust in Apple, and Apple has a responsibility not to abuse that trust," Princeton University Center for Information Technology Policy researcher and regular Ars contributor Timothy B. Lee said.

                        "This incident raises questions about whether Apple is serious about user privacy," Lee continued. "If this was an accident, Apple needs to fix the problem and put in place procedures to make sure it doesn't happen again. If the data is being collected deliberately, perhaps in preparation for a future product, Apple should have clearly notified users and given them an opportunity to opt out."

                        Apple told Congress last July that all location data collected by the iPhone remains private. According to Apple lead counsel Bruce Sewell, Apple does collect anonymous location data from iPhones in an effort to improve its own database of cell tower and WiFi hotspot locations, but that it only does this with user consent. The discovery made by Allan and Warden clearly shows that this is happening constantly without explicit consent like Apple treats GPS, however, and it sure isn't anonymous when it's accessible directly from the user's device.

                        So, is there anywhere you've been in the last year that you don't want anyone to know about?
                        "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
                        Ben Kenobi: "That means I'm doing something right. "

                        Comment


                        • #13
                          Tracking has potential commercial uses.
                          I saw this comment (made by an unidentified member of the public) attached to a news article (simply because it raises an interesting point as to how this could be used):

                          QUOTE 1. It is also the KINDLE!!!! After my arrival to Sydney, KINDLE refused to download FALL OF THE GIANTS, and I was informed to "get in touch with the "home Office" (or something to this effect). KINDLE knew where I was and refused to send me material requested. I totally abhore KINDLE Big Brother behavior for, I did not sign for that! KINDLE's price of download is cheaper in USA at least for $2.- I am appalled by their tracking me through the KINDLE-implant! ENDQUOTE

                          The latest news and headlines from trusted journalists. Get breaking news stories and in-depth coverage with videos and photos.

                          Comment


                          • #14
                            LOL

                            Of course Kindle knows when you are in a different country. YOUR BILLING ADDRESS IS WHAT DETERMINES WHAT YOU ARE ELIGIBLE TO BUY.

                            I created an Amazon account with a fake American address to buy books in US$ when it's cheaper. It's not big brother, it's about copyright licensing and how it's done per country.
                            "The issue is there are still many people out there that use religion as a crutch for bigotry and hate. Like Ben."
                            Ben Kenobi: "That means I'm doing something right. "

                            Comment


                            • #15
                              I am pleased it amuses you, it is good to laugh.

                              I know nothing of Kindle. I read real books made out of real paper.

                              BTW If you access your Amazon account from Canada via your iPhone perhaps service could be denied because "they" know your iPhone is in Canada? The technology appears to be there to do it.

                              Comment

                              Working...
                              X