Perimeter
4/22/2011
01:21 PM
Rob Enderle
Rob Enderle
Commentary
Connect Directly
RSS
E-Mail
50%
50%

What's Good About iPhone's Location Tracking

The iPhone tracking disclosure this week showcases an unfortunate tendency for device manufacturers to focus excessively on their needs and forget those of their users

Over the past week there has been a lot of time spent by seemingly outraged people finding that the iPhone tracks and records the user's location. The problem, as I see it, is that the file isn’t secure -- not that Apple was misusing the information, but there has yet been no identification of anyone misusing that information yet. Granted, now that folks know it is there, that will likely change.

I think the real problem with this capability whether it is found in an Apple or Android device (Android phones have this capability built in as well, and you can generally turn it off) is that it isn’t overt and used for our benefit. If it were, then it not only could be better protected but we might find the rewards greater than the risks. Let me explain.

I’ve actually been a big believer in location-tracking but that is because I’m concerned about protecting loved ones and getting help should I need it quickly. We’ve had a rash of kidnappings for adults and children that could have likely been partially mitigated if these people could be more quickly and easily tracked. In addition, as we age we are at increased risk of heart attack and any of us could have an accident or be attacked where we are away from folks that could hear our cries for help.

A phone that ether had an emergency button which would send our location and our immediate need for assistance would be a life saver. And simply allowing parents to constantly be aware of where their children are would give them piece of mind, and for those watching, a better opportunity to come to the child’s assistance.

But these positive uses of location tracking are rarely implemented: instead, they are used so that advertisers can better target us with sales opportunities. While I don’t see that as particularly evil, neither is it something I want so badly I’m going to risk a predator knowing where my kid is, particularly if I don’t.

I think the general problem here is that there is so much effort to find new and creative ways to monetize personal information that people are forgetting there are real user needs for this information as well.

Thus the vendors conceal, intentionally or not, the collection of this information because they rightly expect we’ll get upset if we find out they are capturing it. If they worked harder to find ways we could use this information for our own benefit, then it would be more overt, and we’d likely have in place rules as to how it needs to be protected, and they could still get the majority of the benefit they initially wanted.

The problem is vendors get so blinded by greed they forget there are real people buying these phones and increasing the efforts to protect these customers might result in a better, and less contentious, solution for everyone.

--Rob Enderle is president and founder of The Enderle Group. Special to Dark Reading.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0607
Published: 2014-07-24
Unrestricted file upload vulnerability in Attachmate Verastream Process Designer (VPD) before R6 SP1 Hotfix 1 allows remote attackers to execute arbitrary code by uploading and launching an executable file.

CVE-2014-1419
Published: 2014-07-24
Race condition in the power policy functions in policy-funcs in acpi-support before 0.142 allows local users to gain privileges via unspecified vectors.

CVE-2014-2360
Published: 2014-07-24
OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules allow remote attackers to execute arbitrary code via packets that report a high battery voltage.

CVE-2014-2361
Published: 2014-07-24
OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules, when BreeZ is used, do not require authentication for reading the site security key, which allows physically proximate attackers to spoof communication by obtaining this key after use of direct hardware access or manual-setup mode.

CVE-2014-2362
Published: 2014-07-24
OleumTech WIO DH2 Wireless Gateway and Sensor Wireless I/O Modules rely exclusively on a time value for entropy in key generation, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by predicting the time of project creation.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Sara Peters hosts a conversation on Botnets and those who fight them.