Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The iPhone is not logging your location. Rather, it’s maintaining a database of Wi-Fi hotspots and cell towers around your current location, some of which may be located more than one hundred miles away from your iPhone, to help your iPhone rapidly and accurately calculate its location when requested

Can Apple locate me based on my geo-tagged Wi-Fi hotspot and cell tower data? No. This data is sent to Apple in an anonymous and encrypted form. Apple cannot identify the source of this data.

I think a lot of folks who spent money on Apple products are going to be happy with this, and for that I'm glad.

But I didn't find this release adequate. Apple is not tracking me -- they are keeping a time-stamped list of nearby access points on my device, which effectively is a huge breadcrumb trail of everywhere I've been and when. Apple doesn't know it's me -- because the data is encrypted, which makes no sense at all. Whether data is encrypted or not is meaningless. Can I go to the Apple server logs and track incoming downloads and associate them with the data or not? I strongly suspect the answer is "yes". If not, that's great, but that wasn't described here.

The killer omission? That Apple has been doing all of this -- which is at the very least controversial -- without informing the users in a manner in which they clearly understood it. The response we see is simply a reaction. The "bug" here is getting caught.

I don't necessarily see anything nefarious at work, but I'm troubled with the idea that Apple was keeping a list of my whereabouts (the nearest access point, for those of you who are literally-minded) without my knowing it. That's a pretty serious breach of user trust, no matter how many times it was covered in the 47-page lawyered-up doc that nobody reads.

But like I said, folks are willing to cut Apple lots of slack, and they deserve it. But hell if I'd want to see something like this happen again, from any manufacturer. I'm not so sure that vendors are getting the point.



Frankly this is doublespeak very similar to the kind used to manufacture this hysteria in the firstplace - the data you're talking about is on your phone Apple doesn't have it, therefore Apple is not tracking you.

Your email is on your phone. Does this mean that Apple has your email? Clearly not, or perhaps we should have 'emailgate' and prevent phones from downloading emails more than 7 days old.

Apple was never keeping a list of your whereabouts.


>they are keeping a time-stamped list of nearby access points on my device, which effectively is a huge breadcrumb trail of everywhere

Read again. They are not. Its not timestamped when "you" where there, but when some anonynous iPhone picked up that particular hotspot. It got then uploaded to Apple and subsequently downloaded onto your iPhone, so that your iPhone can find its location easier.

Wasn't that kinda the obvious reason in the first place?


I'm pretty sure that's true. I'm going to try find some time this evening to animate the points out of the database from my phone to prove it to myself. I'm guessing the animation will show random segments of trails that anonymous iPhone users have travelled around my neighborhoods, but nothing I'll recognize as a trip I've made. (I'll blog about it at bigiain.com if I find anything interesting)


Then you will write a very interesting, but somewhat misleading blog post, just like everyone else has written in the past few weeks.

The point is that the database on your phone is a subset of the greater (global) database mapping wifi and cell access points to location. The local database contains timestamps of when your phone downloaded the information. The global database only contains a list of access points and approximate locations of those access points.

That way, when your phone sees an access point it can look up in the database (locally or globally) and see if this access point has been pinpointed, if it has it will be another tool for your device to provide you with a proper location.

In other words: animating the points in your database will show the first time your phone downloaded information about a specific access point, which will give you a trail of your movements (to a certain extent limited by the factors mentioned above).


That's a pretty serious breach of user trust, no matter how many times it was covered in the 47-page lawyered-up doc that nobody reads.

Yup! The crowdsourcing part (how they initially assembled and now maintain the hotspot database) needs a bit more clarifying. The release glosses over it and people everywhere are instead fretting about the file, even though it's just a cache, a mere fragment of Apple's data, not theirs.

The iPhone UX makes it very obvious that apps are using location services but it never conveys that the iPhone user is contributing data back to Apple, even if anonymously. This is new information for everyone, I guess.


You did agree to the terms of use when you activated your iPhone, correct?


>"The "bug" here is getting caught."

Furthermore Apple implies that they uncovered the but themselves.

    The reason the iPhone stores so much data is a bug we 
    uncovered and plan to fix shortly (see Software Update 
    section below). We don’t think the iPhone needs to store 
    more than seven days of this data.
Again, Apple's use of language is interesting. The phrase, "the iPhone needs to store" is based on functional criteria rather than the economic value which can be garnered from storing and datamining the level of information currently gathered in the crowd sourced database.


I found the language interesting too. It's subtle but exactly the same "you're holding it wrong", refusal to really admit wrong or truly come clean attitude that they displayed with the antenna saga.

It's a very interesting comparison as well with Google who (for example) with Buzz and the Wifi sniffing incident did complete and total mea culpas without reservation. It didn't particularly seem to help Google in those cases so it's hard to argue that Apple needs to do the same, but I do feel they would be better off with a simple and direct "sorry" and a promise to do better rather than a "oh it was just a bug, and we found it ourselves anyway, and by some definitions you're all wrong anyway so there!".


>"Apple doesn't know it's me -- because the data is encrypted"

Actually it is because the data is made anonymous not because it is encrypted. If they do this correctly they really don't know it is you.


This is intensely nerdy, but "encrypted form" can be jargon for what we'd mean by "anonymised" in certain contexts around personally identifiable information.


For those interested in continuing the conversation, I followed this comment up with a HN post: http://news.ycombinator.com/item?id=2490693


It says "anonymous". The answer is yes. If it is possible Apple was lying.


> some of which may be located more than one hundred miles away

Then, I hope that nobody got convicted on the basis of such "accurate" informations...




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: