Tuesday, January 29, 2019

Responsible Corporations: My Privacy Does Matter

Yesterday was a big day in the Apple world, and not in a good way.

Around 4 PM on January 28th, MacRumors, my go-to source for Apple news, began reporting on a serious flaw discovered in the Group FaceTime feature of the latest iOS update. The bug was straightforward and alarming: if you initiated a FaceTime call with someone and then added yourself back into the call as a third participant, an audio bridge would open on the other end, whether or not the person you called ever accepted. In plain terms, you could listen in on someone without their knowledge or consent.

By 11 PM, local television news was running the story. That same night, Apple disabled Group FaceTime on their servers entirely, shutting down the vulnerability before it could spread further.

I went to bed feeling reasonably reassured. Apple has spent years positioning itself as a company that genuinely champions user privacy. It is woven into their marketing, their product announcements, and their public messaging. I had just upgraded a Mac, and one of the first things Mojave presented me with was a notice about privacy and Apple's commitment to protecting it. Their entire privacy page exists as a public declaration of values. I believed them. I still want to.

Then I woke up the next morning.

MacRumors had posted a thread showing that a teenager had discovered this exact bug and reported it to Apple on January 21st, a full seven days before it became public. The timestamps on those posts cannot be faked. Apple had been made aware of a significant privacy vulnerability affecting millions of users, and nothing changed until mainstream media picked up the story.

That is the part that concerns me most.

I am not suggesting Apple acted maliciously. What I am suggesting is that somewhere in the chain between a teenager's bug report and a company-wide response, something failed. Either the report did not reach the right people, or it did and the urgency was not recognized, or, in the worst case scenario, someone knew and was quietly working toward a backend fix before the story got out. Any of those outcomes points to a process problem that a company of Apple's size and stated values should not have.

Technology companies, especially those that have built their brand on privacy and trust, have a responsibility that goes beyond good marketing. When a flaw is reported, the response cannot depend on whether a journalist picks up the story first. Users deserve to know when their security is at risk. Transparency, even when it is uncomfortable, is what actually builds trust over time.

Apple has done remarkable things. I remain a believer in a lot of what they stand for. But this was a stumble, and it deserves to be called one clearly.

Put people above the bottom line. Always.

No comments:

Today, the world feels a little quieter, a little dimmer.

We knew this day would come, but we held onto the hope that there would be more time. John Michael "Ozzy" Osbourne—our beloved Pri...