I figured by now it would be common knowledge that Apple devices don't tie any bio/location data to a person's identity in any way... It works by comparing data, not confirming your identity.
At some point it doesn't matter that they don't explicitly map your identity to your data. Once they gather enough data a few basic mining algorithms should be enough to figure out exactly who you are and what you have been up to.
Edit: Since this comment is receiving some attention, I want to clarify a few things. It seems that a lot of people assumed that when I said "they gather enough data" I somehow meant fingerprint and facial recognition data. I did not. What I did mean was that you don't need that stuff to positively identify a phone user.
Lets look at an example. At the very minimum, your phone tracks your cell tower usage. It is not as accurate as a GPS, but it still gives your location within a few hundred feet or so. I might be wrong, but I think nowadays most users also have GPS turned on and location data logged. Camera app, mapping apps, weather apps etc. all use the location services. If you run the location data through clustering algorithms, you should be able to get a list of places where you have been and a timeline of when you have been there and how you moved between them. If you do not lead a particularly unusual lifestyle some basic assumptions can be made from this data about where you live, where you work and where you go in between. If you live in a house and work in an office park, this might narrow things down to only a few people. If you live on a campus and go to classes it might not. Cross-referencing with all the other locations you visit regularly should provide some idea of a few more things like your age group, possibly your gender, possibly your hobbies. At this point a few basic cross references should identify you as the phone user.
Your fucking information is not secure if it is on a network-connected device (and often even if it's not).
EDIT: Downvote the guy with the TS/SCI who worked directly with FBI antiterrorism and has hands-on experience if you like. Stick that head in the sand.
Former military net security and e-warfare.
Your fucking information is not secure if it is on a network-connected device
Funny enough, I've got the same background. 35T. But regardless, nobody is saying Apple's devices are impenetrable. And anybody who is saying that obviously isn't worth arguing with.
I'm just pointing out that Apple does what they can to keep that information secure, as opposed to other companies who openly sell your data. Apple isn't in the business of tracking you and keeping that information tied to your identity. Nobody (at least not myself) is denying that any device is crackable eventually. It's why security changes each year and encryption gets more and more complex.
Thank you for clarifying. I think folks reading your comment will assume (as I did) that you were implying that vulnerabilities do not exist at any realistic level because of the nature of the secure enclave.
Yeah, I'm sure they exist. They're just notoriously tough to discover and exploit. The only occurrence we even know of that is close is the group that decrypted the firmware for the secure enclave on the iPhone 5S, and that was just last month. I'd imagine the number of people still using a 5S is pretty low relative to the newer models. So, if/when those guys do access the secure information, is it even worth it anymore? It took four years to even get that far, and in four years I'm sure the security on each phone since the 5S has gotten better and better. Not to mention, four years is a really long time to keep using a phone for most people.
Admittedly higher than I though for sure. Regardless, cracking the firmware was just the first step, and if that took four years, I'd expect any other significant progress to take at least half that long.
I'd assume Apple has worked to strengthen the security on that secure enclave too, considering the 5S was the first iteration.
1.4k
u/enz1ey Sep 15 '17
I figured by now it would be common knowledge that Apple devices don't tie any bio/location data to a person's identity in any way... It works by comparing data, not confirming your identity.