Risk
12/29/2010
06:39 PM
50%
50%

Apple May Face More Privacy Lawsuits

Without definitive laws defining data privacy rights, Apple and other companies involved in developing mobile applications are likely to be targeted by consumers turning to the courts for protection.

Top 10 Apple Stories Of 2010
(click image for larger view)
Slideshow: Top 10 Apple Stories Of 2010

Apple and several application developers sued for allegedly misusing the personal data of iPhone and iPad users are likely to face more lawsuits in the future as consumers turn to the courts for privacy protection.

Apple and the creators of Backflip, Dictionary.com, Pandora, The Weather Channel, and other applications were named in two class action lawsuits filed last week in U.S. District Court in San Jose, Calif., The Washington Post reported. The suits seek to prevent the applications from sharing personal data found on iPhones and iPads, including ages, gender, location, and a unique device identifying number that Apple assigns to each of its mobile devices.

The lawsuits come as federal officials debate over what actions government should take to protect privacy as companies look to profit from ad-supported application services on smartphones and other mobile devices. The Federal Trade Commission recommended this month that consumers be offered a no-tracking option before signing up for services, while the Commerce Department favors establishing a code of conduct that businesses could voluntarily agree to follow. Once the commitment is made, businesses would be monitored to ensure the rules are followed.

While privacy is being debated in government, the latest suits are an indication that consumers are turning to the courts for protection and that trend is likely to continue. "I would not be surprise if there were more lawsuits," Kevin D. Pomfret, a lawyer who advises businesses on privacy issues for the national law firm LeClairRyan, told InformationWeek Wednesday. "This is an area where the law is unclear."

Apple did not respond to a request for comment.

One of the lawsuits was filed by the firm KamberLaw on behalf of Jonathan Lalo of Los Angeles County. KamberLaw specializes in digital privacy cases. The second suit was filed by Dallas lawyer Majed Nachawati of Fears and Nachawati, which is looking to represent Texas and California iPhone and iPad users in the class-action complaint. Both lawsuits accuse the companies of violating federal computer fraud and privacy laws.

To avoid being named in a privacy suit, Pomfret is advising companies to consider carefully why they need user data and be sure to use it only for the purposes approved in advance by the owners of that data. In addition, companies need to be sure that data shared with other companies is not used for other purposes without prior approval. "Unfortunately, there's no clear-cut answer right now, because of the uncertainty," he says.

SEE ALSO:

Obama Administration Urges Online Privacy Bill Of Rights

FTC Proposes 'Do Not Track' Option For Internet

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
Dark Reading Live EVENTS
INsecurity - For the Defenders of Enterprise Security
A Dark Reading Conference
While red team conferences focus primarily on new vulnerabilities and security researchers, INsecurity puts security execution, protection, and operations center stage. The primary speakers will be CISOs and leaders in security defense; the blue team will be the focus.
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Tell the sysadmin that we have a situation.
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
[Strategic Security Report] Assessing Cybersecurity Risk
[Strategic Security Report] Assessing Cybersecurity Risk
As cyber attackers become more sophisticated and enterprise defenses become more complex, many enterprises are faced with a complicated question: what is the risk of an IT security breach? This report delivers insight on how today's enterprises evaluate the risks they face. This report also offers a look at security professionals' concerns about a wide variety of threats, including cloud security, mobile security, and the Internet of Things.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.