iOS device tracking - we need details of how to disable (urgently)
Dear Apple,
You might not consider that your users privacy is important, however we do take a different view. It has become clear that iOS devices write location and time information to a clear text file that is then automatically synced via iTunes back to our primary computers. This is not acceptable and you need to make a public statement about why this is happnening and confirming what steps we can take to ensure this is not the default behaviour.
From what I can see this leaves the following attack vectors open:
1 - Direct iOS vulerability expliot, we know that iOS has had a history of vulnerabilities, all it could take is someone directing a user to a pdf file that has an un-disclosed or un-patched vulnerability, this could possibly open this file for access and exploitation
2 - Simple access from backup stored by iTunes on PCs, perhaps it's time to enable encryption by default?? A utility has been released that reads this automatically and plots location over time on a map.
PS - Word of warning to everyone, don't run the utility to plot your location unless you want to give away your location and time to the map provider.