Wednesday April 27, 2011 6:30 pm
Apple finally addresses iPhone location tracking, promises to encrypt data
Today Apple released a Q&A about the location data that's stored on the iPhone. In the statement, the company says broadly that it does not track the iPhone's location, and that the data, which is currently stored in an unprotected file, will be encrypted in the next major update of iOS.
In the statement, Apple admits that iPhones send location data to Apple to maintain a crowd-sourced database of Wi-Fi hotspots and cell phone towers, as many have suspected. However, the company says the locations recorded can be up to 100 miles away from the where the phone actually is, and that the data is sent anonymously.
Apple further explains that it's creating the database to provide better location services on the phone. By using the crowd-sourced locations of cell towers and hotspots, the phone can more quickly locate the user than if it were using GPS satellite data alone. Putting the entire database on every user's phone would be untenable, though, so an iPhone requesting location services accesses a subset, or cache, of the database. It's this data, not necessarily data specifically generated by the user, that's stored in the unencrypted file, "consolidated.db."
At the same time, though, the company effectively admits that retaining such a lengthy and comprehensive location record on the phone—ever since the user upgraded to iOS 4, or about a year for most users—is unnecessary to maintain such a database. Also, backing the file up to a user's computer is clearly not needed either. Apple says it plans to do four things in the next major update of iOS:
- 1) Reduce the size of the file.
- 2) Stop backing up the file.
- 3) Delete the file entirely when location services are turned off.
- 4) Encrypt the file on the phone.
Apple is also specific about when it shares location data with third parties, saying it provides "anonymous crash logs" to developers to help them debug apps from users who have opted in to doing so. Apple's iAds advertising system can also use location to target ads, but Apple says it doesn't provide a user's location data unless the user explicitly approves it.
As for the question of whether the iPhone stores location data even when location services are turned off, as some have reported, the company said that this is a software bug that will also be fixed in the coming iOS update.
The issue of iPhone location tracking came to light last week when researchers described in detail how the device maintains a location database in an unencrypted file called "consolidated.db." The researchers showed how one could easily access the file from a backup and, with a Mac app, see the data points on a map. While imprecise, the data shows generally where the phone had been.
Although the issue first entered the public consciousness last week, others have known about the stored location data for some time, and we found that it's been used as evidence by law enforcement for months. Washington lawmakers have gotten into the fray as well, and some have demanded that Apple explain itself. Many have questioned whether the issue is really that controversial in the first place.
Apple Statement on Location Data, reprinted from Apple's press page.
April 27, 2011
Apple Q&A on Location Data
Apple would like to respond to the questions we have recently received about the gathering and use of location information by our devices.
1. Why is Apple tracking the location of my iPhone?
Apple is not tracking the location of your iPhone. Apple has never done so and has no plans to ever do so.
2. Then why is everyone so concerned about this?
Providing mobile users with fast and accurate location information while preserving their security and privacy has raised some very complex technical issues which are hard to communicate in a soundbite. Users are confused, partly because the creators of this new technology (including Apple) have not provided enough education about these issues to date.
3. Why is my iPhone logging my location?
The iPhone is not logging your location. Rather, it’s maintaining a database of Wi-Fi hotspots and cell towers around your current location, some of which may be located more than one hundred miles away from your iPhone, to help your iPhone rapidly and accurately calculate its location when requested. Calculating a phone’s location using just GPS satellite data can take up to several minutes. iPhone can reduce this time to just a few seconds by using Wi-Fi hotspot and cell tower data to quickly find GPS satellites, and even triangulate its location using just Wi-Fi hotspot and cell tower data when GPS is not available (such as indoors or in basements). These calculations are performed live on the iPhone using a crowd-sourced database of Wi-Fi hotspot and cell tower data that is generated by tens of millions of iPhones sending the geo-tagged locations of nearby Wi-Fi hotspots and cell towers in an anonymous and encrypted form to Apple.
4. Is this crowd-sourced database stored on the iPhone?
The entire crowd-sourced database is too big to store on an iPhone, so we download an appropriate subset (cache) onto each iPhone. This cache is protected but not encrypted, and is backed up in iTunes whenever you back up your iPhone. The backup is encrypted or not, depending on the user settings in iTunes. The location data that researchers are seeing on the iPhone is not the past or present location of the iPhone, but rather the locations of Wi-Fi hotspots and cell towers surrounding the iPhone’s location, which can be more than one hundred miles away from the iPhone. We plan to cease backing up this cache in a software update coming soon (see Software Update section below).
5. Can Apple locate me based on my geo-tagged Wi-Fi hotspot and cell tower data?
No. This data is sent to Apple in an anonymous and encrypted form. Apple cannot identify the source of this data.
6. People have identified up to a year’s worth of location data being stored on the iPhone. Why does my iPhone need so much data in order to assist it in finding my location today?
This data is not the iPhone’s location data—it is a subset (cache) of the crowd-sourced Wi-Fi hotspot and cell tower database which is downloaded from Apple into the iPhone to assist the iPhone in rapidly and accurately calculating location. The reason the iPhone stores so much data is a bug we uncovered and plan to fix shortly (see Software Update section below). We don’t think the iPhone needs to store more than seven days of this data.
7. When I turn off Location Services, why does my iPhone sometimes continue updating its Wi-Fi and cell tower data from Apple’s crowd-sourced database?
It shouldn’t. This is a bug, which we plan to fix shortly (see Software Update section below).
8. What other location data is Apple collecting from the iPhone besides crowd-sourced Wi-Fi hotspot and cell tower data?
Apple is now collecting anonymous traffic data to build a crowd-sourced traffic database with the goal of providing iPhone users an improved traffic service in the next couple of years.
9. Does Apple currently provide any data collected from iPhones to third parties?
We provide anonymous crash logs from users that have opted in to third-party developers to help them debug their apps. Our iAds advertising system can use location as a factor in targeting ads. Location is not shared with any third party or ad unless the user explicitly approves giving the current location to the current ad (for example, to request the ad locate the Target store nearest them).
10. Does Apple believe that personal information security and privacy are important?
Yes, we strongly do. For example, iPhone was the first to ask users to give their permission for each and every app that wanted to use location. Apple will continue to be one of the leaders in strengthening personal information security and privacy.
Sometime in the next few weeks Apple will release a free iOS software update that:
- 1. reduces the size of the crowd-sourced Wi-Fi hotspot and cell tower database cached on the iPhone,
- 2. ceases backing up this cache, and
- 3. deletes this cache entirely when Location Services is turned off.
In the next major iOS software release the cache will also be encrypted on the iPhone.
This article, written by Peter Pachal, originally appeared on PCMag.com and is republished on Gear Live with the permission of Ziff Davis, Inc.
- Related Tags:
- a-gps, apple, consolidated.db, encryption, gps, ios, ios 4, iphone, iphone location tracking, law enforcement, location tracking, privacy, wi-fi