Advertisement Banner
  • Home
  • News
  • Cyber News
  • Contact
No Result
View All Result
  • Home
  • News
  • Cyber News
  • Contact
No Result
View All Result
Wellnessnewshubb
No Result
View All Result
Home Cyber News

Experts claim that iPhone’s analytics data is not anonymousSecurity Affairs

admin by admin
November 23, 2022
in Cyber News


Researchers discovered that analytics data associated with iPhone include Directory Services Identifier (DSID) that could allow identifying users.

Researchers at software company Mysk discovered that analytics data collected by iPhone include the Directory Services Identifier (DSID), which could allow identifying users.

Apple collects both DSID and Apple ID, which means that it can use the former to identify the user and retrieve associated personal information, including full name, phone number, birth date, email, and address.

“Apple uses DSID to uniquely identify Apple ID accounts. DSID is associated with your name, email, and any data in your iCloud account. This is a screenshot of an API call to iCloud, and DSID it can be clearly seen alongside a user’s personal data” reads a Tweet by Mysk.

🚨 New Findings:
🧵 1/6
Apple’s analytics data include an ID called “dsId”. We were able to verify that “dsId” is the “Directory Services Identifier”, an ID that uniquely identifies an iCloud account. Meaning, Apple’s analytics can personally identify you 👇 pic.twitter.com/3DSUFwX3nV

— Mysk 🇨🇦🇩🇪 (@mysk_co) November 21, 2022

According to the experts, this behavior violates the privacy policy of the company that states that “none of the collected information identifies you personally.”

“Personal data is either not logged at all, is subject to privacy preserving techniques such as differential privacy, or is removed from any reports before they’re sent to Apple.” states the policy.

“Knowing the DSID is like knowing your name. It’s one-to-one to your identity,” Tommy Mysk, an app developer and security researcher, told Gizmodo. “All these detailed analytics are going to be linked directly to you. And that’s a problem, because there’s no way to switch it off.”

It is important to highlight that Mysk researchers used a jailbroken iPhone running iOS 14.6 for their tests in order to be able to decrypt the traffic and determine which data are sent back to Apple.

The experts also tested an iPhone running iOS 16, but security measures implemented by Apple could not allow them to “jailbreak” the device to inspect the traffic. Anyway, the experts argue that a jailbroken phone would send the same data as the latest iOS version.

Apple has yet to respond to a request for comment on the issue.

Earlier this month, Mysk researchers also discovered that Apple collects analytics information even when the users switch off the iPhone setting “Share iPhone Analytics.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, iPhone)




Share On






Source link

Previous Post

Supreme Court defends independence of Election Commissioner –

Next Post

Elon Musk wants encrypted messaging for Twitter. It might not be that simple.

Next Post

Elon Musk wants encrypted messaging for Twitter. It might not be that simple.

Recommended

India urges G20 nations to come on board to regulate crypto

5 months ago

Vitalik Buterin sounds warning over risks of DeFi

4 months ago

© 2022 Law Enforcement News Hubb All rights reserved.

Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Privacy Policy and Terms & Conditions.

Navigate Site

  • Home
  • News
  • Cyber News
  • Contact

Newsletter Sign Up.

No Result
View All Result
  • Home
  • News
  • Cyber News
  • Contact

© 2022 Law Enforcement News Hubb All rights reserved.