I haven't seen any mentions of this data being sent to Apple. Until that comes out, I'd prefer to turn this tracking off but I don't particularly care about it.
It's not like anyone can get access to it without breaking into your computer and it's not a real time feed. On top of the fact that it's only recording the gps location of the cell tower you're connected to (supposedly) it seems about as much of a security issue as my 4square feed.
I'm not sure why there's a tendency to evaluate the security / privacy implications of technology at an individual level when it has societal reach.
Yes in your instance, evaluated from an individual perspective, it seems absurd to worry about some imagined nefarious types breaking into your computer to get data like this.
But analysing the implications from an individual perspective is akin to forgoing fuzz testing on a web app because you'd never type all those sorts of inputs in as a normal user.
These things should always be analysed from a societal perspective. Having this type of data unencrypted means the father going through a child custody case may find all his movements lifted by a private investigator, the local politician who frequents a red light district may be at even greater risk of blackmail, and the small-town activist may find themselves harassed in new and interesting ways by local police of dubious moral character.
When presented with plausible scenarios like this there are certainly people who would still shrug and say, "I still don't care". That's fine - they're just not the people you'd trust to debate these issues, just like you wouldn't trust them debating internal security issues in a corporate environment.
Bit of an unfair mischaracterisation of my position don't you think? People can still conceive of the social implications of security / privacy issues and disagree in informed debate.
However it appears that a certain segment of the community only get as far as analysing the immediate, personal impact of said security / privacy issues before giving the thumbs up. To them, there is no value in discussing / considering the wider social implications, because they don't actually care.
Perhaps that tendency should be called the narcissistic defect of security / privacy analysis.
Why do you equate not caring with giving the thumbs up? Perhaps people have considered the wider social implications and have decided that the cost of caring exceeds the potential damage.
Some number of people will lose their phone and their ex-spouse will find it and blackmail them with their location data (but not any other data on the phone). I have tabulated the total damage to society caused by this problem and arrived at a total of X. I have also tabulated the total cost of fixing this problem and arrived at a total of Y. Which is bigger, X or Y?
Limiting analysis to the personal impact of privacy / security issues arising in our rapidly evolving society is simply poor analysis and certainly not helpful in contributing to a well-planned, well-designed future society.
This narcissistic / short-term mindset is unhealthy, and is manifested in discussions around security ("I'm boring, who wants to hack me?") / privacy ("I'm boring, who's interested in me?") / liberty ("I have nothing to hide!") / environment (tragedy of the commons).
Someone working up a societal cost calculation as you outline clearly does not suffer from the narcissistic defect of security / privacy analysis that obviously rankles me. As long as people take a broader view it's perfectly reasonable to disagree on the importance / severity of a particular security / privacy breach.
In this particular instance the cost of modifying iOS to encrypt consolidated.db, store less data points, or allow users to easily opt out would be negligible.
If it was a little Silicon Valley startup they'd potentially go down in flames as HNers howled at them for taking such an amateur and reckless approach to users personal data. It'd certainly be a software defect that would quickly be patched by any little software house.
Comments
I haven't seen any mentions of this data being sent to Apple. Until that comes out, I'd prefer to turn this tracking off but I don't particularly care about it.
It's not like anyone can get access to it without breaking into your computer and it's not a real time feed. On top of the fact that it's only recording the gps location of the cell tower you're connected to (supposedly) it seems about as much of a security issue as my 4square feed.
I'm not sure why there's a tendency to evaluate the security / privacy implications of technology at an individual level when it has societal reach.
Yes in your instance, evaluated from an individual perspective, it seems absurd to worry about some imagined nefarious types breaking into your computer to get data like this.
But analysing the implications from an individual perspective is akin to forgoing fuzz testing on a web app because you'd never type all those sorts of inputs in as a normal user.
These things should always be analysed from a societal perspective. Having this type of data unencrypted means the father going through a child custody case may find all his movements lifted by a private investigator, the local politician who frequents a red light district may be at even greater risk of blackmail, and the small-town activist may find themselves harassed in new and interesting ways by local police of dubious moral character.
When presented with plausible scenarios like this there are certainly people who would still shrug and say, "I still don't care". That's fine - they're just not the people you'd trust to debate these issues, just like you wouldn't trust them debating internal security issues in a corporate environment.
It sounds like the only people you want to debate with are people who already agree with you.
Bit of an unfair mischaracterisation of my position don't you think? People can still conceive of the social implications of security / privacy issues and disagree in informed debate.
However it appears that a certain segment of the community only get as far as analysing the immediate, personal impact of said security / privacy issues before giving the thumbs up. To them, there is no value in discussing / considering the wider social implications, because they don't actually care.
Perhaps that tendency should be called the narcissistic defect of security / privacy analysis.
Why do you equate not caring with giving the thumbs up? Perhaps people have considered the wider social implications and have decided that the cost of caring exceeds the potential damage.
Some number of people will lose their phone and their ex-spouse will find it and blackmail them with their location data (but not any other data on the phone). I have tabulated the total damage to society caused by this problem and arrived at a total of X. I have also tabulated the total cost of fixing this problem and arrived at a total of Y. Which is bigger, X or Y?
Limiting analysis to the personal impact of privacy / security issues arising in our rapidly evolving society is simply poor analysis and certainly not helpful in contributing to a well-planned, well-designed future society.
This narcissistic / short-term mindset is unhealthy, and is manifested in discussions around security ("I'm boring, who wants to hack me?") / privacy ("I'm boring, who's interested in me?") / liberty ("I have nothing to hide!") / environment (tragedy of the commons).
Someone working up a societal cost calculation as you outline clearly does not suffer from the narcissistic defect of security / privacy analysis that obviously rankles me. As long as people take a broader view it's perfectly reasonable to disagree on the importance / severity of a particular security / privacy breach.
In this particular instance the cost of modifying iOS to encrypt consolidated.db, store less data points, or allow users to easily opt out would be negligible.
If it was a little Silicon Valley startup they'd potentially go down in flames as HNers howled at them for taking such an amateur and reckless approach to users personal data. It'd certainly be a software defect that would quickly be patched by any little software house.
From everything I have read, it doesn't go to Apple at all and the data isn't very accurate. This is a non-starter to me.
Kinda like saying one didn't inhale.
But it's cooler to PANIC!!!
edit: just looked at the article and the image at the top. Ha.