<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/iphone_developer_steals_customers_phone_numbers_calls_them.php" />
  <link rel="self" type="application/atom+xml" href="http://www.readwriteweb.com/atom.xml" />
  <id>tag:www.readwriteweb.com,2011:/1/tag:www.readwriteweb.com,2009://1.16582-</id>
  <updated>2011-08-16T16:33:05Z</updated>
  <title>Comments for iPhone Developer Steals Customers&apos; Phone Numbers, Calls Them</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.35-en</generator>
  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16582</id>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/iphone_developer_steals_customers_phone_numbers_calls_them.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.readwriteweb.com/cgi-bin/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=16582" title="iPhone Developer Steals Customers' Phone Numbers, Calls Them" />
    <published>2009-09-30T13:30:49Z</published>
    <updated>2009-09-30T14:52:45Z</updated>
    <title>iPhone Developer Steals Customers&apos; Phone Numbers, Calls Them</title>
    <summary>Company calls customers in attempt to sell paid version of mobile app Within iTunes&apos; user ratings section of iPhone application mogoRoad, a real-time traffic monitoring tool available in Switzerland, several users claim to have received phone calls from the development company behind the mobile software. Reportedly, the company is asking the app owners if they...</summary>
    <author>
      <name>Sarah Perez</name>
      
    </author>
    
    <category term="Apple" />
    
    <category term="Mobile" />
    
    <category term="NYT" />
    
    <category term="News" />
    
    <content type="html" xml:lang="en" xml:base="http://www.readwriteweb.com/">
      <![CDATA[<em><strong><p>Company calls customers in attempt to sell paid version of mobile app</p></strong></em>

<p><img src="http://www.readwriteweb.com/images/iphone2.jpg" />Within iTunes' user ratings section of iPhone application <a href="http://www.mogoroad.ch/?lang=en">mogoRoad</a>, a real-time traffic monitoring tool available in Switzerland, several users claim to have received phone calls from the development company behind the mobile software. Reportedly, the company is asking the app owners if they would like to purchase the paid version of the application. While unsolicited sales calls are annoying and intrusive, the bigger issue here is how did the company get its customers' phone numbers to begin with? According to mogoRoad, the information came from Apple. </p>]]>
      <![CDATA[

<p><img align="right" src="http://www.readwriteweb.com/images/mogoroad logo.png" />The recipients of the unwanted calls said that they were contacted a few weeks after the initial installation of the mogoRoad application. An operator would then try to sell them the paid version of the mobile software. If pressed as to how the company got access to their phone number, the operator would generally respond that the information was provided by Apple. </p>

<p>That seems unlikely since Apple does <u>not</u> provide this sort of private information to App Store developers nor does it provide direct access to that information via the iPhone SDK (software development kit), the tool used by developers to build their mobile apps. </p>

<h2>Apple Doesn't Provide Phone Numbers, but They Do Provide Access</h2>

<p>However, it's not <em>entirely</em> inaccurate of the company to say that Apple did provide them with the customers' phone numbers. Although Apple doesn't directly give out this info, they do provide a relatively easy way for any app developer to retrieve mobile numbers from the phone. In other words, Apple didn't give out the numbers in question, they just provided access to them.&#160; </p>

<p><img align="left" src="http://www.readwriteweb.com/images/iphone_keypad.gif" />Although mogoRoad won't admit it, the most likely explanation as to how they retrieved the phone numbers involves the use of an undocumented feature which allows any Apple iPhone/iPod Touch application to access the phone number of the device on which it is installed. In an article on tech blog <a href="http://arstechnica.com/apple/news/2009/01/iphone-dev-user-phone-numbers.ars">Ars Technica</a> from earlier this year, the process of doing so was described as "a shockingly easy thing to do:" </p>

<p><em>Apple sneaks in a hidden symbolic link between the app's sandboxed preferences and a global preferences property list...Peek in Library/Preferences with &quot;ls -a&quot;. You'll find a symbolic link to /private/var/mobile/Library/Preferences/.GlobalPreferences.plist, which is where (among other items), you'll find a preference called SBFormattedPhoneNumber. <strong>This preference provides exactly what the name implies: the user's phone number formatted to the current locale.</strong></em></p>

<p>In checking with multiple iPhone developers this morning, we confirmed that the trick still works as described above.</p>

<h2>It's Not a Bug, It's a Feature</h2>

<p>Believe it or not, this isn't actually a security hole in need of patching - it's more of a feature. "It's important to remember that perfectly legit applications can reach your phone number plus your entire address book as well," Ars Technica blogger Erica Sadun <a href="http://arstechnica.com/apple/news/2009/01/iphone-dev-user-phone-numbers.ars">wrote</a> back in January. "Applications can also obtain personal information from most of the iPhone file system..."</p>

<p>While the large majority of app developers out there would never do anything quite so nefarious as what mogoRoad did and undoubtedly wouldn't want to risk alienating their customers in this fashion, it's unsettling to know that they <em>could.</em> And every time you install a mobile app, you're putting yourself at risk. </p>

<p>As of now, Apple hasn't officially responded to requests for comment as to how they will proceed with regards to this situation, either to us or to the blog originally reporting this story, French site <a href="http://translate.google.com/translate?u=http://www.mac4ever.com/news/48159/exclu_iphone_une_vraie_passoire_pour_certaines_donnees_personnelles/&amp;hl=en&amp;langpair=auto|en&amp;tbb=1&amp;ie=UTF-8">Mac4Ever</a>. However, given that the development company has clearly abused an undocumented feature, that should be enough to get them booted out of the App Store...hopefully for good. </p>

<p><em>Many thanks to </em><a href="http://www.macworld.com/article/143047/2009/09/phone_hole.html?lsrc=rss_weblogs_iphonecentral"><em>MacWord</em></a><em>, which pointed us to this story. </em></p>]]>
    </content>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16582-comment:284506</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16582" type="text/html" href="http://www.readwriteweb.com/archives/iphone_developer_steals_customers_phone_numbers_calls_them.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/iphone_developer_steals_customers_phone_numbers_calls_them.php#c284506" />
    <title>Comment from Internet Marketing Expert on 2010-12-05</title>
    <author>
        <name>Internet Marketing Expert</name>
        <uri>http://www.thomaspaylor.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.thomaspaylor.com">
        <![CDATA[<p>Its scary to think that these apps can have full access to your phone. Imagine people been able to see what your doing 24/7, its scary stuff. However, the new <p><a href="http://www.thomaspaylor.com/iphone-ebay-application" rel="nofollow">iPhone eBay application</a> is well smart</p></p>]]>
    </content>
    <published>2010-12-05T21:42:03Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16582-comment:218793</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16582" type="text/html" href="http://www.readwriteweb.com/archives/iphone_developer_steals_customers_phone_numbers_calls_them.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/iphone_developer_steals_customers_phone_numbers_calls_them.php#c218793" />
    <title>Comment from melymoocow on 2010-06-19</title>
    <author>
        <name>melymoocow</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>I downloaded 3 apps for my iphone from the app store and had all my email accounts and youtube account and facebook account hacked and stolen, people need to be far more informed </p>]]>
    </content>
    <published>2010-06-19T12:49:30Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16582-comment:185377</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16582" type="text/html" href="http://www.readwriteweb.com/archives/iphone_developer_steals_customers_phone_numbers_calls_them.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/iphone_developer_steals_customers_phone_numbers_calls_them.php#c185377" />
    <title>Comment from Chris on 2010-02-02</title>
    <author>
        <name>Chris</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>This was a really dumb move by this  <a href="http://www.PhoneFreelancer.com" rel="nofollow">iphone developer </a>, like did he think he was going to get away with this? And now he is banned from the App store forever and is probably missing out on tons of revenue. No bueno.</p>]]>
    </content>
    <published>2010-02-03T01:37:52Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16582-comment:185141</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16582" type="text/html" href="http://www.readwriteweb.com/archives/iphone_developer_steals_customers_phone_numbers_calls_them.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/iphone_developer_steals_customers_phone_numbers_calls_them.php#c185141" />
    <title>Comment from Will on 2010-02-02</title>
    <author>
        <name>Will</name>
        <uri>http://uk.linkedin.com/in/wharford</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://uk.linkedin.com/in/wharford">
        <![CDATA[<p>Hopefully I can be of assistance to up and coming developers. I specialise in the recruitment of iPhone developers and I am a great contact to have if you’re a developer. I have access to some of the best App development companies and I am passionate about what I do!</p>

<p>Drop me an Email: wharford@keypeople.co.uk<br />
Connect with me on LinkedIn, <br />
<br />
<br />
iPhone LinkedIn Jobs<br />
/in/wharford (I accept all requests)<br />
Or call me 00441727 817641<br />
</p>]]>
    </content>
    <published>2010-02-02T16:12:09Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16582-comment:160776</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16582" type="text/html" href="http://www.readwriteweb.com/archives/iphone_developer_steals_customers_phone_numbers_calls_them.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/iphone_developer_steals_customers_phone_numbers_calls_them.php#c160776" />
    <title>Comment from Jesse on 2009-10-02</title>
    <author>
        <name>Jesse</name>
        <uri>http://jessearmand.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://jessearmand.com">
        <![CDATA[<p>Peter,</p>

<p>There's an installer for that, Cydia and Icy, and maybe other installers based on Cydia system.</p>

<p>The only problem is, not all people would want to jailbreak their phone. Every time there's an OS upgrade, jailbreaking needs to be done with care.</p>

<p>Apple will be overloaded to also maintain this type of installer.</p>]]>
    </content>
    <published>2009-10-02T11:47:17Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16582-comment:160508</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16582" type="text/html" href="http://www.readwriteweb.com/archives/iphone_developer_steals_customers_phone_numbers_calls_them.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/iphone_developer_steals_customers_phone_numbers_calls_them.php#c160508" />
    <title>Comment from Son Nguyen on 2009-09-30</title>
    <author>
        <name>Son Nguyen</name>
        <uri>http://www.adspeed.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.adspeed.com">
        <![CDATA[<p>This just waits to happen and finally it did. Platform providers like Facebook or Apple must give users more levels to tune their privacy preferences. Now apps just has too much power and some will no doubt try to exploit that.</p>]]>
    </content>
    <published>2009-09-30T22:32:47Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16582-comment:160483</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16582" type="text/html" href="http://www.readwriteweb.com/archives/iphone_developer_steals_customers_phone_numbers_calls_them.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/iphone_developer_steals_customers_phone_numbers_calls_them.php#c160483" />
    <title>Comment from Peter on 2009-09-30</title>
    <author>
        <name>Peter</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Ah yes.  The sound of a false sense of security being shattered.</p>

<p>I've always laughed when the Apple Fanbois talked about how Apple needs to control the store because, if it didn't, you'd have all these apps that steal your personal information.  Apple checks these apps to make sure they're not doing anything untoward.</p>

<p>Well, it turns out that they're not checking after all--or at least not hard enough.</p>

<p>In my opinion, Apple should:</p>

<p>1.  Create an installer so that anybody can install whatever Apps they want.  This way, third-party developers don't have to get any approval from Apple.  But Apple doesn't host, advertise, or do anything with their Apps.<br />
2.  If you want to be in the App Store, you submit to a far more rigorous examination, including source code.  Appropriate NDAs will need to be negotiated between you and Apple.<br />
3.  Anyone who doesn't agree to the above is out of the App Store and on their own.</p>

<p>By doing #1, Apple is not ruining the application experience for those who are interested.  In fact, it will generate a wider variety of Apps, versus the hundreds of fart Apps and tip calculators that clog up the store.</p>

<p>By doing #2, customers can choose to only shop at the App Store where they know it's safe, that applications have been reviewed, etc.</p>]]>
    </content>
    <published>2009-09-30T19:03:15Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16582-comment:160453</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16582" type="text/html" href="http://www.readwriteweb.com/archives/iphone_developer_steals_customers_phone_numbers_calls_them.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/iphone_developer_steals_customers_phone_numbers_calls_them.php#c160453" />
    <title>Comment from richy on 2009-09-30</title>
    <author>
        <name>richy</name>
        <uri>http://www.wonderwebmarketing.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.wonderwebmarketing.com">
        <![CDATA[<p>Why am I not one bit surprised at this story ? It's no different to any apps on anything. I'm sure it's exactly the same on all apps on things like facebook etc...</p>]]>
    </content>
    <published>2009-09-30T15:38:15Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16582-comment:160450</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16582" type="text/html" href="http://www.readwriteweb.com/archives/iphone_developer_steals_customers_phone_numbers_calls_them.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/iphone_developer_steals_customers_phone_numbers_calls_them.php#c160450" />
    <title>Comment from BWI on 2009-09-30</title>
    <author>
        <name>BWI</name>
        <uri>http://www.bestwebimage.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.bestwebimage.com">
        <![CDATA[<p>That is classic. That certainly should be a controlled "feature" by Apple.</p>]]>
    </content>
    <published>2009-09-30T14:58:42Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16582-comment:160449</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16582" type="text/html" href="http://www.readwriteweb.com/archives/iphone_developer_steals_customers_phone_numbers_calls_them.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/iphone_developer_steals_customers_phone_numbers_calls_them.php#c160449" />
    <title>Comment from Vincent on 2009-09-30</title>
    <author>
        <name>Vincent</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>It has been known for a long time that every application have full access to your Contacts on your iPhone without any warning.</p>

<p>Why the hell does Apple allows this. People have a false sense of security when they install an application.</p>]]>
    </content>
    <published>2009-09-30T14:45:45Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2009://1.16582-comment:160446</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2009://1.16582" type="text/html" href="http://www.readwriteweb.com/archives/iphone_developer_steals_customers_phone_numbers_calls_them.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/iphone_developer_steals_customers_phone_numbers_calls_them.php#c160446" />
    <title>Comment from ITrush on 2009-09-30</title>
    <author>
        <name>ITrush</name>
        <uri>http://www.itrush.com</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.itrush.com">
        <![CDATA[<p>What the?!! Hmm, how the hek on earth those company manage to get our phone numbers?</p>]]>
    </content>
    <published>2009-09-30T14:34:27Z</published>
  </entry>

</feed>
