{"id":799,"date":"2007-06-10T15:33:31","date_gmt":"2007-06-10T23:33:31","guid":{"rendered":"\/?p=799"},"modified":"2007-06-10T15:33:31","modified_gmt":"2007-06-10T23:33:31","slug":"more-on-the-itunes-approach-to-privacy","status":"publish","type":"post","link":"https:\/\/www.identityblog.com\/?p=799","title":{"rendered":"More on the iTunes approach to privacy"},"content":{"rendered":"<p>Reading more about Apple&#39;s decision to insert <a href=\"\/?p=797\">user&#39;s names and email addresses<\/a> in the songs they download from iTunes, I came across some <a href=\"http:\/\/www.macworld.com\/weblogs\/editors\/2006\/01\/ministore\/\">related information <\/a>in an excellent <a href=\"http:\/\/www.macworld.com\/\">Macworld <\/a>article by <a href=\"http:\/\/www.macworld.com\/info\/contact\/form.php?e=Rob Griffiths&amp;t=e\" class=\"broken_link\">Rob Griffiths<\/a>:<\/p>\n<p style=\"background: #f5f6f7; margin-left: 30px\">Yesterday, Apple\u00e2\u20ac\u2122s iTunes 6.0.2 update was released, and offered these features, according to the Read Me:<\/p>\n<p style=\"margin-left: 60px\">iTunes 6.0.2 includes stability and performance improvements over iTunes 6.0.1.<\/p>\n<p style=\"background: #f5f6f7; margin-left: 30px\">What it also offered, but didn\u00e2\u20ac\u2122t bother to disclose, was the addition of a bit of potential spyware to the iTunes interface. As reported originally on <a target=\"_blank\" href=\"http:\/\/since1968.com\/\">since1968.com<\/a>, and then followed-up on <a target=\"_blank\" href=\"http:\/\/www.boingboing.net\/2006\/01\/11\/itunes_update_spies_.html\">boingboing<\/a> and other sites, the new iTunes MiniStore, which appears directly below the song list area in the main iTunes window, watches what you click on in iTunes and sends that information across the Web to a remote server. When you double-click a song to play in your Library or playlists, the display in the mini-store changes to reflect \u00e2\u20ac\u02dcmatches\u00e2\u20ac\u2122 based on what\u00e2\u20ac\u2122s been selected, as seen below.<\/p>\n<p><img loading=\"lazy\" width=\"480\" src=\"http:\/\/www.macworld.com\/2006\/01\/images\/content\/itunesministore.jpg\" height=\"270\" style=\"margin-left: 30px; width: 480px; height: 270px\" \/><\/p>\n<p style=\"background: #f5f6f7; margin-left: 30px\">In order to do this, the music store must obviously know what you\u00e2\u20ac\u2122re listening to. It learns this information via a packet of information sent each time you play a song via a double-click. This data is sent without your explicit permission, and as far as I can tell, there are no Apple privacy policies that cover that transfer of information. It\u00e2\u20ac\u2122s also unclear exactly what data is being sent. (Is it just song and title? Or does it include your Apple music store ID, which would tie the song info directly to your personal data?) And although Apple now assures us that the data is not collected, that information is not made clear to users when they begin using iTunes.<\/p>\n<p style=\"background: #f5f6f7; margin-left: 30px\">The MiniStore can be easily disabled\u00e2\u20ac\u201djust hit Shift-Command-M, or choose Edit: Hide MiniStore, and it\u00e2\u20ac\u2122s gone. Once hidden, no more data is transmitted, as <a target=\"_blank\" href=\"http:\/\/www.mcelhearn.com\/article.php?story=20060111150127268\">confirmed by Kirk McElhearn<\/a> using the Unix program <code>tcpdump<\/code>, which watches traffic sent over your network connection. Disable the MiniStore, and your private listening habits will stay just that\u00e2\u20ac\u201dprivate.<\/p>\n<p style=\"background: #f5f6f7; margin-left: 30px\">However, this isn\u00e2\u20ac\u2122t about the MiniStore itself. It\u00e2\u20ac\u2122s about Apple\u00e2\u20ac\u2122s attitude in rolling this change out to the millions of iTunes users, without as much as a peep about what\u00e2\u20ac\u2122s going on behind the scenes. Consider, for example, if Microsoft had done such a thing with a minor Office update\u00e2\u20ac\u201dsay they started collecting data on the names of the files you were editing, in the hopes of selling you preformatted templates to help with future similar projects. If they did this in a minor update, and without telling anyone that the data were being transmitted, there would be universal outrage over this potential attack on our privacy. And now Apple\u00e2\u20ac\u2122s gone and done basically the exact same thing.<\/p>\n<p style=\"background: #f5f6f7; margin-left: 30px\">Personally, I am quite upset with Apple\u00e2\u20ac\u2122s decision-making in this case, and I hope others are as well.<\/p>\n<p style=\"margin-left: 30px\">No company, even one I admire as much as Apple (I did spend nearly five years of my life working there), should start transmitting personal data over the Internet without my explicit permission and a clear explanation of how it\u00e2\u20ac\u2122s being used. In addition, if a company <em>is<\/em> collecting this information, I have a right to know exactly what\u00e2\u20ac\u2122s being collected, and what the company plans on doing with my personal information.<\/p>\n<p style=\"background: #f5f6f7; margin-left: 30px\">The good news is, Apple tells us that the information is not actually being collected. The data sent is used to update the MiniStore and then discarded. If you think about it, this makes sense\u00e2\u20ac\u201dimagine the size of the data files they would accumulate with millions of users and what must be hundreds of millions of songs played each day. But Apple should tell us as much, so that we can all relax a bit about sharing our listening habits with Apple.<\/p>\n<p style=\"background: #f5f6f7; margin-left: 30px\">Apple should amend iTunes to clearly disclose what data the program is transmitting and how it\u00e2\u20ac\u2122s being used. There should be a dialog box that pops up the first time iTunes runs, explaining exactly how the MiniStore works. If Apple had just included that yesterday \u00e2\u20ac\u201d or even some information in the Read Me, then I wouldn\u00e2\u20ac\u2122t have even raised this as an issue. A little transparency and openness can go a long way to easing privacy fears.<\/p>\n<p>As interesting as the article are the 166 comments on it. About half seem to think it&#39;s fine for Apple to collect the information without consent. Oops. I shouldn&#39;t have said &#8220;collect&#8221; &#8211; or at least that&#39;s Apple&#39;s spin on this. It seems that even though the information is sent in (through a third party), Apple doesn&#39;t actually &#8220;collect&#8221; it, since it discards the information after &#8220;processing it&#8221;. So &#8220;collect&#8221; seems to mean &#8220;retain in raw form.&#8221; The iTune supporters make it clear they &#8220;don&#39;t think&#8221; Apple would use the information to create a profile of their tastes. Customer loyalty is a beautiful thing. This is the stuff that great ads are made of.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Reading more about Apple&#39;s decision to insert user&#39;s names and email addresses in the songs they download from iTunes, I came across some related information in an excellent Macworld article by Rob Griffiths: Yesterday, Apple\u00e2\u20ac\u2122s iTunes 6.0.2 update was released, and offered these features, according to the Read Me: iTunes 6.0.2 includes stability and performance &hellip; <a href=\"https:\/\/www.identityblog.com\/?p=799\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">More on the iTunes approach to privacy<\/span><\/a><\/p>\n","protected":false},"author":68,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/799"}],"collection":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/users\/68"}],"replies":[{"embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=799"}],"version-history":[{"count":0,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=\/wp\/v2\/posts\/799\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=799"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=799"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.identityblog.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=799"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}