4 ms·
Worse, even the WSJ article has the whiff of sensationalism. For example, this is what you find very near the top of the article: These phones don't keep secre
by CodeMage 16y ago
Worse, even the WSJ article has the whiff of sensationalism. For example, this is what you find very near the top of the article:
These phones don't keep secrets. They are sharing this personal data widely and regularly, a Wall Street Journal investigation has found.
An examination of 101 popular smartphone "apps" -- games and other software applications for iPhone and Android phones -- showed that 56 transmitted the phone's unique device ID to other companies without users' awareness or consent.
Later on, the UDID is called "supercookie" and the article emphasizes the fact that it "can never be changed or turned off".
That would be truly scary if they showed some proof that the user, as a person, could be easily identified by their phone's UDID. Okay, the carrier has that information, but who else has it? Somehow I don't think that the relationship between your phone's UDID and your identity is something easily available to just about anyone.
- davidu 16y agoAre you kidding? The UDID and the phone owner's name are easily correlated. As soon as you register for an account on a game or app, you will connect UDID to your email or first/last name. As soon as that happens, it could easily end up in Rapleaf or another system for other data brokers to get access to. The connection just has to happen once, in one app, for all of them to benefit from it. On the plus side, an app getting this data could auto-register you since it knows you based on your UDID as soon as you install the app, just sending you an email confirmation and a password. :-)
- gyardley 16y agoIn order to get any online data broker interested in your data, you have to tie it to their browser cookie. On iOS, this is hard, thanks to sandboxing. You pretty much have to redirect the user to the Safari browser with the UDID in the query string - which is a pretty crap experience for the user, which is why it's rarely done. Even then you've only gotten the data into the mobile browser, which is not what the data market wants to pay for right now. People still predominantly buy things through their desktop computers. I don't know if it's vanity or narcissism or what, but everyone assumes their 'data' has a lot of commercial value. It doesn't. Back when I was running an iPhone analytics startup, I looked into all of this stuff. Wasn't even worth the development work to monetize it.
- michaelbuckbee 16y agoWould you have to actually redirect them to Safari or could you do something like load a hidden webview? (not quite sure of the right terminology here) I was thinking the iOS equivalent of a webpage with a hidden iFrame.
- gyardley 16y agoCookies are sandboxed, so the cookie you write in your in-app 1x1 pixel webview can't be read by the Safari browser, making it useless. If we could cookie the user properly it's what I'd use for analytics instead of the UDID.
- rgrieselhuber 16y agoLaunch Safari to have them complete registration online?
- michaelbuckbee 16y agoThanks, that makes sense.
- davidu 16y agoWhy do you think you need safari or a browser? There are plenty of other (and easier) ways to make HTTP connections in iOS and implement account registration.
- gyardley 16y agoImplementing account registration, collecting an e-mail, and then using that e-mail as a unique ID to append data to the data broker's database -- this is possible, but rightly considered PII, so no data broker does this without user opt-in. (In this case the risk exceeds the rewards anyway, but that's another discussion.) If you're talking about setting a cookie with the data broker's user ID, which then can be read by the data broker on other websites - which is the standard way of shuffling non-PII data around in the absence of an explicit user opt-in - then this doesn't work due to iOS' application sandboxing. You can set a cookie with the data broker's user ID, but the data broker won't be able to retrieve it when the user's off elsewhere surfing the web, when it matters.
- pilif 16y agoI'm not even sure the carrier has the information. At least in countries where the iPhone is sold unlocked. The UDID has nothing to do with the IMEI/IMSI which are both known by the carriers.
- heresy 16y agoI'd be worried if the carrier has this info. I bought the iPhone 4 from Apple, the micro SIM from vodafone, two separate unconnected transactions.
- jacquesm 16y agoSo what stops the carrier to tie your billing information (which I presume has your name and address on it) to the SIM purchase ? Every time you switch that phone on that phone ID is tied to the SIM on the network.