Palm’s Pres Spying on Palm Pre Users and Reporting Back to Palm   - 820 Views,

Summary: Holy privacy and security issue! A Palm Pre user who is also a securitygeekstud has discovered that Palm Pres (or should that be Palm Pri? Palm Prie? What is the plural of "Pre"?) are spying on Palm Pre users and on how they are using their Palm Pre, and reporting back to Palm!

Previous Article « AT&T’s New ToS Prohibits Customers from Class Action Suits Against AT&T
Read Next Article » Phishers Turn to SMS with Text Message Phishing

  Follow Anne on Twitter     Friend Anne on Facebook

Holy privacy and security issue! A Palm Pre user who is also a securitygeekstud has discovered that Palm Pres (or should that be Palm Pri? Palm Prie? What is the plural of “Pre”?) are tracking Palm Pre users and how they are using their Palm Pre, and reporting back to Palm!

The narcing Palm Pre issue was discovered by Joey Hess, who posted the full details of his discovery on his blog over at Kitenet.net. As Hess explains, “I’ve been taking a closer look at the WebOS side of my Palm Pre tonight, and I noticed that it periodically uploads information to Palm, Inc..”

Talk about a thing that makes you go “Hmmm.”

Hess goes on to explain that “The first thing sent is intended to be my GPS location. It’s the same location I get if I open the map app on the Pre. Not very accurate in this case, but I’ve seen it be accurate enough to find my house before.”

Hess then noted that the Palm Pre was also reporting “every WebOS app I use, and for how long.”

According to Hess, this information is reported back to Palm by the Palm Pre on a daily basis. The culprit is a routine on the Palm Pre called “uploadd”, which sends the information via the web (using an https command) to the server at ps.palmws.com.

Hess also explains he has disabled it on his own Palm Pre by commenting out the line which executes the command in the file found at /etc/event.d/uploadd, noting that whenever there is an OS upgrade to the Pre, it may reinstate the command.

Said a Palm spokesperson, when questioned about the practice, “Our privacy policy is like many policies in the industry and includes very detailed language about potential scenarios in which we might use a customer’s information, all toward a goal of offering a great user experience. For instance, when location based services are used, we collect their information to give them relevant local results in Google Maps. We appreciate the trust that users give us with their information, and have no intention to violate that trust.”

Of course that and a dollar won’t even get you a cup of coffee.

You can read Hess’ full article, which includes copies of all the culprit codes, here.

Palm’s Pres Spying on Palm Pre Users and Reporting Back to Palm

 Follow Anne on Twitter

 Twitter Explained in Plain English

 Friend Anne on Facebook

Previous Article « AT&T’s New ToS Prohibits Customers from Class Action Suits Against AT&T
Read Next Article » Phishers Turn to SMS with Text Message Phishing

Read more:

»  Apple Throws Down Gauntlet - Disables iTunes Sync for Palm Pre and Other Smart Phones

»  Text Message Warning of Gang Initiation at Walmart a Hoax that Won’t Die

»  List of 6,500 AIDS and HIV Patients Accidentally Emailed Out

»  FlexiSpy Cell Phone Tapping Software

For additional similar stories check out our archives on Privacy, Security

NOTE: We never, ever, ever will recommend any product or service on this site that we have not regularly used ourselves and do not wholeheartedly believe in. That said, in some cases after being very pleased with a product or service, we may enter into a relationship with the provider of that product or service such that if someone purchases that product or service based on our recommendation, we may get a small payment. Such payments go towards the upkeep of the Internet Patrol.

 

No Comments »

No comments yet.

RSS feed for comments on this post.

Leave a comment

Warning! All comments which contain URLs and are clearly just spam to generate a link back to the URL will be deleted on sight. Don't bother wasting your time!

If you are going to include a URL in your comment,
please keep it under 25 characters in length,
or use TinyURL to shorten it before including it in your comment.

Line and paragraph breaks are automatic, your email address is never displayed.
HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)


If you have not posted a comment here before, we apologize for having to ask you to enter the letters and numbers you see in the image above to validate your comment, but we are being attacked by thousands of comment form spams every day! You only need to do this once; once you have successfuly posted a comment here you will not be asked to do this again. Thank you for your understanding!

 
 This article first appeared on 8/13/2009
The Internet Patrol
Patrolling the Internet for You!