Guide to the TechWeb Network


The InformationWeek -- Blogs
Over The Air

Mobility Breifing Center -- Sponsored by Windows Mobile
Topics:   Mobile

  • Email this page E-mail this page
  • |  Print this page Print this page
  • |   Bookmark and Share

Hacker Claims Apple Can Spy On iPhone Users, Disable Apps Remotely


Posted by Eric Zeman, Aug 7, 2008 10:42 AM

Apple may have opened up the iPhone to third-party applications, but it is keeping a very close eye on those apps. According to hacker Jonathan Zdziarski, the iPhone can "phone home" to tell Apple what apps are installed, and if Apple doesn't like what it sees on your iPhone, it can kill the offending application. Updated!

Oh man. Apple, please tell me you didn't open this can of worms for real. The iPhone Apps Store, fun while it may be, already has had its fair share of negative press. Several apps have been squashed with no explanation from Apple, and the SDK has angered many developers, who feel Apple's control over what sort of apps they can develop is onerous and restrictive.

Turns out that's not the half of it. MacRumors is reporting that Apple has set up a URL to keep a list of applications that it doesn't like. So far, nothing is on that list. In Zdziarski's words:

This suggests that the iPhone calls home once in a while to find out what applications it should turn off. At the moment, no apps have been blacklisted, but by all appearances, this has been added to disable applications that the user has already downloaded and paid for, if Apple so chooses to shut them down.

I discovered this doing a forensic examination of an iPhone 3G. It appears to be tucked away in a configuration file deep inside CoreLocation.

MacRumors suggests that Apple will most likely only use this functionality to kill malware or other code it deems dangerous. But what about unsanctioned applications that are downloaded to unlocked iPhones? Will Apple keep tabs on the applications that unlocked iPhone users download and install? Will it kill apps it doesn't like, even if the user has paid for it?

All these questions remain unanswered.

The bigger one that lingers in my mind is, if Apple is keeping tabs on the applications I am downloading, what else is it keeping tabs on? My phone calls? My text messages? My browsing history? The type of content I chose to consume? I surely hope not, as that's a major breach of privacy.

Update:

Apple has clarified what this blacklist is for:

An "informed source" at Apple has [said] the mysterious iPhone app blacklist striking fear in the hearts of iPhone-toting privacy nerds everywhere actually isn't for remotely disabling apps. Nope, it's actually a CoreLocation blacklist—in other words, a list of apps not allowed to access CoreLocation (which would be why it was buried there). So actually, it's protecting your privacy by keeping naughty apps from knowing where you are.

/hysteria

« Microsoft Starts Taking (Expensive) Surface Orders | Main | Apple MobileMe Memo Shows Jobs Grown Soft »



Tomorrow's CIO: Do you have what it takes?
Find out at the 2008 InformationWeek 500 Conference
Sept. 14-16, St. Regis Resort, Monarch Beach, Calif.


Sign up now for the weekly InformationWeek Blog Newsletter.


This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




Mobile Video



  1. Windows Vista: The OS About Nothing
  2. You Thought Vista Was Bad?
  3. Google Chrome: Browser Or Cloud Operating System?
  4. Apple Nixes 'Pull My Finger' App, Even Though It's A Gas
  5. Sarah Palin's Babygate And The Future Of Journalism


  1. Radical Desktops Deliver Power To The People. But What About IT?
  2. Need Disaster Recovery On The Cheap? Think Virtualization
  3. No Virtualizing Without A License
  4. Smart Stuff: The State Of Business Intelligence 2008
  5. Down To Business: Are Technology Leaders Focusing Too Much On The Small Stuff?
  6. Rolling Review Wrap-Up: Vendors' RFP Responses Make The Case For Switching

 
 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007
AUGUST 2007
JULY 2007
  JUNE 2007
MAY 2007
APRIL 2007
MARCH 2007
FEBRUARY 2007
JANUARY 2007
DECEMBER 2006
NOVEMBER 2006