Risk
12/29/2010
06:39 PM
50%
50%

Apple May Face More Privacy Lawsuits

Without definitive laws defining data privacy rights, Apple and other companies involved in developing mobile applications are likely to be targeted by consumers turning to the courts for protection.

Top 10 Apple Stories Of 2010
(click image for larger view)
Slideshow: Top 10 Apple Stories Of 2010

Apple and several application developers sued for allegedly misusing the personal data of iPhone and iPad users are likely to face more lawsuits in the future as consumers turn to the courts for privacy protection.

Apple and the creators of Backflip, Dictionary.com, Pandora, The Weather Channel, and other applications were named in two class action lawsuits filed last week in U.S. District Court in San Jose, Calif., The Washington Post reported. The suits seek to prevent the applications from sharing personal data found on iPhones and iPads, including ages, gender, location, and a unique device identifying number that Apple assigns to each of its mobile devices.

The lawsuits come as federal officials debate over what actions government should take to protect privacy as companies look to profit from ad-supported application services on smartphones and other mobile devices. The Federal Trade Commission recommended this month that consumers be offered a no-tracking option before signing up for services, while the Commerce Department favors establishing a code of conduct that businesses could voluntarily agree to follow. Once the commitment is made, businesses would be monitored to ensure the rules are followed.

While privacy is being debated in government, the latest suits are an indication that consumers are turning to the courts for protection and that trend is likely to continue. "I would not be surprise if there were more lawsuits," Kevin D. Pomfret, a lawyer who advises businesses on privacy issues for the national law firm LeClairRyan, told InformationWeek Wednesday. "This is an area where the law is unclear."

Apple did not respond to a request for comment.

One of the lawsuits was filed by the firm KamberLaw on behalf of Jonathan Lalo of Los Angeles County. KamberLaw specializes in digital privacy cases. The second suit was filed by Dallas lawyer Majed Nachawati of Fears and Nachawati, which is looking to represent Texas and California iPhone and iPad users in the class-action complaint. Both lawsuits accuse the companies of violating federal computer fraud and privacy laws.

To avoid being named in a privacy suit, Pomfret is advising companies to consider carefully why they need user data and be sure to use it only for the purposes approved in advance by the owners of that data. In addition, companies need to be sure that data shared with other companies is not used for other purposes without prior approval. "Unfortunately, there's no clear-cut answer right now, because of the uncertainty," he says.

SEE ALSO:

Obama Administration Urges Online Privacy Bill Of Rights

FTC Proposes 'Do Not Track' Option For Internet

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-6090
Published: 2015-04-27
Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) DataMappingEditorCommands, (2) DatastoreEditorCommands, and (3) IEGEditorCommands servlets in IBM Curam Social Program Management (SPM) 5.2 SP6 before EP6, 6.0 SP2 before EP26, 6.0.3 before 6.0.3.0 iFix8, 6.0.4 before 6.0.4.5 iFix...

CVE-2014-6092
Published: 2015-04-27
IBM Curam Social Program Management (SPM) 5.2 before SP6 EP6, 6.0 SP2 before EP26, 6.0.4 before 6.0.4.6, and 6.0.5 before 6.0.5.6 requires failed-login handling for web-service accounts to have the same lockout policy as for standard user accounts, which makes it easier for remote attackers to cause...

CVE-2015-0113
Published: 2015-04-27
The Jazz help system in IBM Rational Collaborative Lifecycle Management 4.0 through 5.0.2, Rational Quality Manager 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Team Concert 4.0 through 4.0.7 and 5.0 through 5.0.2, Rational Requirements Composer 4.0 through 4.0.7, Rational DOORS Next Generation...

CVE-2015-0174
Published: 2015-04-27
The SNMP implementation in IBM WebSphere Application Server (WAS) 8.5 before 8.5.5.5 does not properly handle configuration data, which allows remote authenticated users to obtain sensitive information via unspecified vectors.

CVE-2015-0175
Published: 2015-04-27
IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 does not properly implement authData elements, which allows remote authenticated users to gain privileges via unspecified vectors.

Dark Reading Radio
Archived Dark Reading Radio
Join security and risk expert John Pironti and Dark Reading Editor-in-Chief Tim Wilson for a live online discussion of the sea-changing shift in security strategy and the many ways it is affecting IT and business.