Is Apple Truly as Pro-Privacy as they Suggest? Evidence of Listening in and a Recent Major Facetime Bug Put Apple’s Public Stance in Question

April 1, 2019

Apple faced public scrutiny when viral videos surfacedshowing a glaringbugwith Apple’s FaceTime feature that allowed the caller to hear conversations andeven see video from the person being called beforethat person accepted or rejected the call. The bug appearsto only appear during group chats (chats with more than 2 people), but thishasn’t stopped people from disablingFaceTime entirely. In response to the bug, Eva Galperin,director of cybersecurity at ElectricFrontier Foundation, a leading international non-profitdedicated to digital privacy rights, brazenly wrote“Throw your iPhone into the sea.”

…this FaceTime bug follows the recent trend of not-so-privacy-conscious news stories related to Apple products.

Given that Apple frequently touts itself as being pro-privacy, this accident has left consumers wondering whether that pro-privacy stance is truly genuine. These concerns were exacerbated by the fact that media outlets recently began reporting that Grant Thompson, a 14-year-old out of Tucson, Arizona had noticed the bug more than a week before the issue became public. Thompson told his mother, a licensed attorney, about the issue and she reportedly “tried everything she could think of to get Apple’s attention,” including emailing, calling, and tweeting at Apple’s CEO Tim Cook, and even faxing a letter on her law firm’s letterhead.

Importantly, this FaceTime bug follows the recenttrend of not-so-privacy-conscious news stories related to Apple products. Alongwith a 2014leak of celebrities’ private iCloud photos, some consumershad also recently been growing increasingly paranoidabout receiving advertisements for products related to something they had beentalking about out loud when the phone was in the room, even when the phone wasnot in use at the time. This sparked huge concern that Apple was listening into consumers and selling their information to third-party advertisers.

Sandy Parakilas, a former operations manager forFacebook, has saidthat he thinks large companies listening in to non-phone conversations is “veryvery unlikely” because collecting data constantly from iPhones would be tooexpensive. However, another cybersecurity expert explainedthat because the iPhone’s microphone, loaded with AI assistants, necessarilyhas to be able to be triggered by vocal commands like “Hey Siri,” the iPhone isconstantly listening for those designated “trigger words.” This mechanism couldjust as easily allow Apple to listen in for trigger words that relate toproducts that certain advertisers request. Did the consumer mention the word“cold” or “heater”? Then perhaps that person will receive an ad from a heatingrepair company that Apple has contracted with. Similarly, a person mentioning“Disney World,” “Miami,” or the word “vacation,” a certain number of timescould just as easily trigger an ad from a travel agency or airline. Although itis difficultto discover exactly what the trigger wordsare because of various encryptions, the possibilitieswith this technology are endless. The ads could be set to be displayed only ifspecific trigger words are said a certain amount of times within a certainperiod of days, or perhaps only if they are said in combination with other triggerwords. Another expert explained that this listening in might happen but that“companies know so much about you already, they probably don’t need toeavesdrop.”

Ina meeting with Congressmen, Apple specifically denied usingthese trigger words to listen in to its customers, but did admit,“Apple does not and cannot monitor what [third-party app] developers do withthe customer data they have collected, or prevent the onward transfer of thatdata, nor do we have the ability to ensure a developer’s compliance with theirown privacy policies or local law.”

Apple has said that they will fix the FaceTime bug bythe end of the week, butthis has not stopped lawsuits and government investigations from ensuing. Anopportunistic attorney from Houston, Larry Williams II, filedsuitfor negligence, product liability, misrepresentation, and breach of warranty againstApple, claiming that the FaceTime bug allowed an unknown person to eavesdrop onhis private conversation with a client. Williams is seeking compensatory andpunitive damages against Apple and claims that Apple failed to notify users ofthe risks of using FaceTime and responded slowly to the risk, a sentiment expressedby other commenters as well. Furthermore, Letitia James, theAttorney General of New York, announcedthat her office would be opening an investigation into the FaceTime bug citingthat the “FaceTime breach is a serious threat to the security and privacy ofthe millions of New Yorkers who have put their trust in Apple and its productsover the years.”It is unclear howlawsuits against Apple or New York’s investigation will turn out; however, whatcan definitely be said is that trust in Apple has slowly been eroding as privacyconcerns continue to fill the news. Likely, the last thing Apple wants is tohave its reputation anywhere near Facebook who has been the subject of numerousprivacy hearings and investigations.

Sebastian Brana, 31 February 2019