Forgot your password?
typodupeerror
Privacy Cellphones Your Rights Online

Palm Pre Reports Your Location and Usage To Palm 314

Posted by Soulskill
from the caught-palm-red-handed dept.
AceJohnny writes "Joey Hess found that his Palm Pre was ratting on him. It turns out the Pre periodically uploads detailed information about the user to Palm, including the names of installed apps, application usage (and crashes), as well as GPS coordinates. This, of course, is without user consent or control. The only way he found to disable the uploads was to modify system files."
This discussion has been archived. No new comments can be posted.

Palm Pre Reports Your Location and Usage To Palm

Comments Filter:
  • by masterlogan2000 (1608973) on Wednesday August 12, 2009 @01:16PM (#29040643)
    Did Palm not think that someone would figure this out? I wonder what kind of backlash there will be about this and how much more negative impact it will have on the Palm brand.
  • the fine print (Score:5, Insightful)

    by alain94040 (785132) * on Wednesday August 12, 2009 @01:17PM (#29040657) Homepage

    Let's see if you can find the trick in Palm's privacy policy:

    Personal information is information directly identifiable to you, such as your name, address, email address, and phone number, as well as other non-public information associated with such information. Some examples of how we collect and use personal information include ... [ a list that sounds pretty safe and reasonable]

    The operating word is Some examples: legally, they don't say that the list is exhaustive and that they don't collect information any other way. So the long list of nice looking collection is just a decoy!

    --
    FairSoftware.net [fairsoftware.net] -- iPhone dev jobs for geeks by geeks

  • Boycott (Score:5, Funny)

    by sakdoctor (1087155) on Wednesday August 12, 2009 @01:17PM (#29040659) Homepage

    Ok, add them to the list.
    Actually it's getting hard to keep track. Should we start a wiki?

  • User Consent ... (Score:5, Informative)

    by neonprimetime (528653) on Wednesday August 12, 2009 @01:22PM (#29040753)
    Story says...

    This, of course, is without user consent or control.

    But From Palm Infocenter, they say [palminfocenter.com]

    Palm's own "Terms and Conditions" statement, along with their Privacy policy, detail that Palm basically maintains it has the right to indefinitely collect, process, store and share this information. Users must accept this multipage collection of fine-print waivers and disclaimers in full during the initial device setup process before being able to utilize the device.
  • Uncool (Score:5, Interesting)

    by sweatyboatman (457800) <sweatyboatman AT hotmail DOT com> on Wednesday August 12, 2009 @01:22PM (#29040761) Homepage Journal

    I read the privacy policy [palm.com] and it doesn't really seem like it's built to cover this kind of snooping.

    And then there's this:

    You may choose whether or not to provide your personal information to us. If you choose not to do so, you can continue to interact with Palm, but you may not be able to take advantage of certain products, services, offers, or options that depend on personal information.

    So is there a website or a setting on the Pre to disable this thing. TFA seems to say there isn't.

    I mean, there's utility in understanding how people are using your device. But not letting your users know you're uploading daily usage stats and not giving them a way to turn it off?

    Truly Uncool.

    • by Late Adopter (1492849) on Wednesday August 12, 2009 @01:56PM (#29041293)
      The initial setup asks you how want to use your location information, and the "Location Services" app lets you change this at any time. I'm looking at the options under that app now, all of which can be switched off:
      • Auto Locate: Your location will be automatically provided to applications that request it.
      • Use GPS: Improves accuracy but can impact battery life
      • Geotag Photos: Stores the GPS coordinates of your location when you use the camera
      • Background Data Collection: Allows Google to automatically collect anonymouse location data to improve the quality of location services.
  • by wowbagger (69688) on Wednesday August 12, 2009 @01:32PM (#29040919) Homepage Journal

    OK, I can see sending what applications are installed and what crashes have occurred given the user's explicit permission - I allow my Ubuntu boxes to participate in the "popularity contest" wherein what apps I install are (anonymously) logged, and I will frequently send crash reports to help get the cause of the crash fixed.

    In both of those cases *I* decide if it happens, and I was informed of the data being uploaded.

    But automatically reporting my GPS locations - HELL NO!!!

    Yes, the Pre is a phone - as such it MUST, BY LAW be able to report its location to 911 (here in the US, natch). My phone (which is NOT a Pre) has been configured to turn GPS off for anything OTHER than E911. If I found out that it was NOT abiding by that selection - that it was sending position data to anyone other than E911 - then not only would I be terminating my cell contract, I would be filing suit against the makers of the phone AND the cell carrier.

    Again, I can see why Palm would want apps installed and crash data - but WHAT DAMN BUSINESS is it of theirs to know position?!?!

  • by Anonymous Coward on Wednesday August 12, 2009 @01:37PM (#29041001)

    You know, that total control of their users and the things they can and can't do. Apple should not control their users like that, it's just...

    Oh wait, you mean someone else than Apple is doing that?

    Damn you Microsoft, always controlling your users....

    Oh wait, you mean it's neither Apple or Microsoft?

    So, you zealots who always bash on Apple and Microsoft... what FUD will you say to protect your precious Palm now? And wasn't Google's Android doing something similar too?

    The solution is easy: get a cellphone that's JUST A GODAMN PHONE.

  • by db32 (862117) on Wednesday August 12, 2009 @01:44PM (#29041103) Journal
    In the spirit of blaming Apple for Palm's misbehavior with their iTunes stunt please respond here with how this is also Apples fault.
    • by Xserv (909355) on Wednesday August 12, 2009 @01:54PM (#29041247)

      In the spirit of blaming Apple for Palm's misbehavior with their iTunes stunt please respond here with how this is also Apples fault.

      I'll give it a shot: There's an app for that!"

      I digress.

      - xserv

    • by Al Dimond (792444) on Wednesday August 12, 2009 @02:02PM (#29041381) Journal

      Ah, the resident Apple fanboys. Always so defensive. Clearly this story has nothing to do with Apple, and nobody has suggested that it does.

      Now I'm pretty well distanced from the Palm-iTunes shenanigans, not owning any portable music player nor running an OS that iTunes supports. I think there's a pretty narrow range of belief systems that could lead to the conclusion that Palm's behavior is worse than Apple's in that case. First, if you believe that vertical monopolies are generally a good thing, and that protection of them is in everyone's interest. And, second, if you believe that Apple is good no matter what they do. Although I certainly recognize that Apple was within their rights legally, Palm's actions made both their device and Apple's software more useful and Apple's made both less useful. If you think Apple's behavior is better hand in your geek card.

  • by Tikkun (992269) on Wednesday August 12, 2009 @01:53PM (#29041241) Homepage
    Although I am not your customer, were I your customer, I would gladly be a beta tester and give you all sorts of useful information (automated or otherwise) about how I used your products.

    This being said, I would hope that you would have the courtesy of asking me to opt-in, rather than assuming that you own my usage habits.
  • TFA Text (Score:5, Informative)

    by AceJohnny (253840) <jlargentaye AT gmail DOT com> on Wednesday August 12, 2009 @01:59PM (#29041335) Journal

    Woops, looks like /. is hammering the server. Here's a copy of the text (as of now):

    I've been taking a closer look at the WebOS side of my Palm Pre tonight, and I noticed that it periodically uploads information to Palm, Inc.

    The first thing sent is intended to be my GPS location. It's the same location I get if I open the map app on the Pre. Not very accurate in this case, but I've seen it be accurate enough to find my house before.

    { "errorCode": 0, "timestamp": 1249855555954.000000, "latitude": 36.594108, "longitude": -82.183260, "horizAccuracy": 2523, "heading": 0, "velocity": 0, "altitude": 0, "vertAccuracy": 0 }

    Here they can tell every WebOS app I use, and for how long.

    { "appid": "com.palm.app.phone", "event": "close", "timestamp": 1250006362 }
    { "appid": "com.palm.app.messaging", "event": "launch", "timestamp": 1250006422 }
    { "appid": "com.palm.app.messaging", "event": "close", "timestamp": 1250006446 }

    It sends the above info on a daily basis.

    2009-08-10t09:15:10z upload /var/context/pending/1249895710-contextfile.gz.contextlog ok rdx-30681971
    2009-08-11t09:15:10z upload /var/context/pending/1249982110-contextfile.gz.contextlog ok rdx-31306808

    There is also some info that is recorded when a WebOS app crashes. Now, I've seen WebOS crash hard a time or two, but it turns out apps are crashing fairly frequently behind the scenes, and each such crash is logged and a system state snapshot taken. At least some of these are uploaded, though if things are crashing a whole lot it will be throttled.

    2009-08-09T17:01:22Z upload /var/log/rdxd/pending/rdxd_log_59.tgz OK RDX-30246857
    2009-08-09T17:05:36Z upload /var/log/rdxd/pending/rdxd_log_26.tgz OK RDX-30249465
    2009-08-09T17:09:11Z upload /var/log/rdxd/pending/rdxd_log_56.tgz OK RDX-30252374
    2009-08-09T17:11:46Z upload /var/log/rdxd/pending/rdxd_log_70.tgz OK RDX-30253958
    2009-08-09T17:16:29Z upload /var/log/rdxd/pending/rdxd_log_67.tgz ERR_UPLOAD_THROTTLED_DAILY
    2009-08-09T17:17:28Z upload /var/log/rdxd/pending/rdxd_log_51.tgz ERR_UPLOAD_THROTTLED_DAILY
    2009-08-09T17:20:40Z upload /var/log/rdxd/pending/rdxd_log_21.tgz ERR_UPLOAD_THROTTLED_DAILY

    Each tarball contains a kernel dmesg, syslog, a manifest.txt listing all installed ipkg packages (including third-party apps), a backtrace of the crash, a df (from which they can tell I'm using Debian on the phone), and ps -f output listing all processes owned by root (but not by joey).

    The uploading is handled by uploadd, which reads /etc/uploadd.conf:

    [SERVER=rdx]
    RepositoryURL=https:///palmcsext/prefRequest?prefkey=APPLICATIONS,RDX_SRV
    UploadURL=https:///palmcsext/RDFileReceiver

    [SERVER=context]
    RepositoryURL=https:///palmcsext/prefRequest?prefkey=APPLICATIONS,RDX_SRV
    UploadURL=https:////palmcsext/RDFileReceiver

    The "HOST" this is sent to via https is ps.palmws.com.

    My approach to disable this, which may not stick across WebOS upgrades, was to comment out the 'exec' line in /etc/event.d/uploadd and reboot. However, then I noticed a contextupload process running. This is started by dbus, so the best way to disable it seems to be: rm /usr/bin/contextupload

    BTW, since Palm has lawyers, they have a privacy policy, which covers their ass fairly well regarding all this, without going into details or making clear that the above data is being uploaded.

  • by SwashbucklingCowboy (727629) on Wednesday August 12, 2009 @02:08PM (#29041451)

    What idiot thought doing this without user opt-in was a good idea?

  • by tony.damato (13665) on Wednesday August 12, 2009 @02:13PM (#29041539)

    http://www.precentral.net/fyi-pre-reports-your-location-palm [precentral.net]

    When PreCentral's people asked Palm about this, their official statement to them in part was:

            Our goal has been to follow industry best practices on data collection, use, and encryption. Like most EULAs and privacy policies, though, the terms tend to get pretty detailed about potential scenarios. And because the terms are meant to notify users about all possible variations, we wanted to err on the side of over notifying rather than under notifying users through the terms of use. So there's really nothing here "beyond the norm" for a EULA or privacy policy.

            The provision you've quoted explains why Palm might collect user information. For example, we collect and transmit users' email addresses, email content, contact lists, etc. to provide WebOS services such as back-up and restore for the purpose of backing up that data and helping users restore the data if needed (in that case, it would not be limited to just the email address collected at registration). If users someday make purchases on their device through the Apps Catalog, then we would also collect payment information to process the transaction.

            At all times, we'd be strictly bound by our privacy policy. Our privacy policy, like virtually all others in the industry, contemplate our using data to provide services users have requested, improve our products and services (hence the reference to Palm's own "sales and marketing" in the privacy policy), troubleshoot, etc. We also refer to affiliates because Palm is a global company, and we may need to transmit data from our European subsidiary to the parent company. We're obviously not a conglomerate with many different subs and affiliates, but the terms specifically mention subs and affiliates so that we can comply with European data protection laws that require us to spell out that data collected by a European sub can be transmitted to another part of the company.

  • by Mr.Fork (633378) <edward.j.reddy@g m a i l . c om> on Wednesday August 12, 2009 @02:16PM (#29041581) Journal
    Canada's privacy laws disallows this, especially not notifying the user. As soon as it leaks out to the CRTC and the Privacy Commish, they may disallow this device for sale in Canada later this month.

    But my god, what was Palm thinking? Disappointing.
  • by Stu101 (1031686) on Wednesday August 12, 2009 @02:22PM (#29041669)

    If this is true, it strikes at the very heart of the products saleability. The pre is quite the phone in geek worlds, which unfortunatly for them, tend to be the ones that care about stuff like this!

    By doing this they have alienated a real core market that could have made the Pre a good geek phone rather than a has been phone.

  • Hack it! (Score:3, Insightful)

    by spaceyhackerlady (462530) on Wednesday August 12, 2009 @03:08PM (#29042363)

    So why not hack the thing so it sends what you want it to send? Somewhere innocuous, somewhere whimsical, or just random locations. You could have fun with this.

    "Yes, I really was at the North Pole yesterday. And in Paris the day before. Isn't air travel great!"

    ...laura

Machines that have broken down will work perfectly when the repairman arrives.

Working...