Risk
12/29/2010
06:39 PM
50%
50%

Apple May Face More Privacy Lawsuits

Without definitive laws defining data privacy rights, Apple and other companies involved in developing mobile applications are likely to be targeted by consumers turning to the courts for protection.

Top 10 Apple Stories Of 2010
(click image for larger view)
Slideshow: Top 10 Apple Stories Of 2010

Apple and several application developers sued for allegedly misusing the personal data of iPhone and iPad users are likely to face more lawsuits in the future as consumers turn to the courts for privacy protection.

Apple and the creators of Backflip, Dictionary.com, Pandora, The Weather Channel, and other applications were named in two class action lawsuits filed last week in U.S. District Court in San Jose, Calif., The Washington Post reported. The suits seek to prevent the applications from sharing personal data found on iPhones and iPads, including ages, gender, location, and a unique device identifying number that Apple assigns to each of its mobile devices.

The lawsuits come as federal officials debate over what actions government should take to protect privacy as companies look to profit from ad-supported application services on smartphones and other mobile devices. The Federal Trade Commission recommended this month that consumers be offered a no-tracking option before signing up for services, while the Commerce Department favors establishing a code of conduct that businesses could voluntarily agree to follow. Once the commitment is made, businesses would be monitored to ensure the rules are followed.

While privacy is being debated in government, the latest suits are an indication that consumers are turning to the courts for protection and that trend is likely to continue. "I would not be surprise if there were more lawsuits," Kevin D. Pomfret, a lawyer who advises businesses on privacy issues for the national law firm LeClairRyan, told InformationWeek Wednesday. "This is an area where the law is unclear."

Apple did not respond to a request for comment.

One of the lawsuits was filed by the firm KamberLaw on behalf of Jonathan Lalo of Los Angeles County. KamberLaw specializes in digital privacy cases. The second suit was filed by Dallas lawyer Majed Nachawati of Fears and Nachawati, which is looking to represent Texas and California iPhone and iPad users in the class-action complaint. Both lawsuits accuse the companies of violating federal computer fraud and privacy laws.

To avoid being named in a privacy suit, Pomfret is advising companies to consider carefully why they need user data and be sure to use it only for the purposes approved in advance by the owners of that data. In addition, companies need to be sure that data shared with other companies is not used for other purposes without prior approval. "Unfortunately, there's no clear-cut answer right now, because of the uncertainty," he says.

SEE ALSO:

Obama Administration Urges Online Privacy Bill Of Rights

FTC Proposes 'Do Not Track' Option For Internet

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2382
Published: 2014-11-20
The DfDiskLo.sys driver in Faronics Deep Freeze Standard and Enterprise 8.10 and earlier allows local administrators to cause a denial of service (crash) and execute arbitrary code via a crafted IOCTL request that writes to arbitrary memory locations, related to the IofCallDriver function.

CVE-2014-3625
Published: 2014-11-20
Directory traversal vulnerability in Pivitol Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.

CVE-2014-8387
Published: 2014-11-20
cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrary commands via shell metacharacters in the pinghost parameter to ping.cgi.

CVE-2014-8493
Published: 2014-11-20
ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted request to Forms/access_cwmp_1.

CVE-2014-8767
Published: 2014-11-20
Integer underflow in the olsr_print function in tcpdump 3.9.6 through 4.6.2, when in verbose mode, allows remote attackers to cause a denial of service (crash) via a crafted length value in an OLSR frame.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?