You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

📢 Newsroom Update

Apple introduces powerful new iPad mini built for Apple Intelligence. Learn more >

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

UDID security concern in replacement iPad

I bought an iPad a few weeks ago. After about a week, it developed an issue where it would randomly register taps on one side of the screen. I took it in to an Apple Store and they replaced the iPad with a new one for free (thanks). I asked the Apple Store employee whether I was getting a refurbished iPad or a new one, and he said it was a new one for sure. The replacement iPad came out of a brown OEM-looking box with no charger or manuals. It was wrapped in plastic.

I took the new iPad home from the Apple Store and it works great. However, I noticed a few strange things. First, when I downloaded the Amazon Kindle app from iTunes, it would not let me register because it said my device was already registered to someone else. I had to call Amazon tech support and have them deregister the device, which they said was registered to someone else. In order to do so, I had to look up the iPad's UDID and give it to Amazon. Then, just today, I tried the Pandora app. To my surprise, it already had several stations already preset. Not my stations. Then I went to the settings in Pandora and it said I was logged in as kXXXXX@gmail.com! I assume this person is the previous owner of this iPad, or at least one with the same UDID.

So my questions are these:

1. Was my replacement iPad really new or is it refurbished?
2. Even though the Apple Store guy performed a wipe of my settings, will whoever gets my old iPad after it is refurbished be able to see my email address if he/she downloads Pandora?
3. Isn't this kind of a major security issue for apps that use UDID to identify the device?

iPad 16gb wifi, Other OS

Posted on May 30, 2010 10:55 PM

Reply
9 replies

May 30, 2010 11:15 PM in response to yoshjosh

yoshjosh wrote:


1. Was my replacement iPad really new or is it refurbished?


It's clearly been used. Take it back, and explain; request a new one

2. Even though the Apple Store guy performed a wipe of my settings, will whoever gets my old iPad after it is refurbished be able to see my email address if he/she downloads Pandora?


If he did a full wipe, then no.

3. Isn't this kind of a major security issue for apps that use UDID to identify the device?


It's certainly an issue, but it doesn't seem to happen very often, going by the traffic on these boards (it would be the same for iPhone and iPod Touch for those apps).

May 30, 2010 11:32 PM in response to nick101

Well, presumably Apple did a full wipe of the iPad it gave me as a replacement, and some of the previous owner's settings were retained by some apps (Kindle and Pandora), as well as identifying info (email address). I don't know how you can be so sure that my settings and info won't be retained by my old iPad's next owner if they refurbish it despite the wipe. The fact that it's not popping up in the forums doesn't reassure me a whole lot.

Jun 27, 2010 1:47 PM in response to yoshjosh

This very same thing happened to me, and the people at the local Apple store had the nerve to suggest that someone must have hacked my iTunes account!! I had the exact same Pandora issue, and discovered someone else's searches in Kayak Flights. After the store's refusal to acknowledge that they had indeed been incorrect and the replacement was a refurb, we demanded (and eventually got) a full refund. But like the original poster, now I'm concerned about my private data that got left behind! Apple, anything to say here? I've lost any confidence in your ability to safeguard my private information (or to tell the truth about whether replacement parts are new or not!)

Jun 27, 2010 3:24 PM in response to missnc

I would send feedback here:

http://www.apple.com/feedback/ipad.html

This is quite disconcerting, seems however to be an issue with the apps using device info and tying it to an account/user - it would also be worth e-mailing the pandora team as I suspect this is a possibility they hadn't considered - at the very least any apps identifying a previous account (on first app run) via device info, should perhaps ask if the user wants to resurrect an old account and ask for some verification, or ask if the user wants to tie the device to a new user.

Jun 28, 2010 7:33 AM in response to yoshjosh

This is apparently an issue that is known by Pandora. Quoting from their blog:

"IMPORTANT NOTE: You should always sign out of Pandora before you sell, return or loan your iPad to anyone, as wiping the iPad or changing your Pandora password may not break the association between your account and that device."

http://blog.pandora.com/mt/mt-search.cgi?blog_id=25&tag=Pandora%20on%20your%20iP ad&limit=20

How many other apps have this "feature"?

UDID security concern in replacement iPad

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.