Watch CBS News

Apple Plots Non-Optional End of Privacy for iPhone Users

HTML5 -- the new browser language system that will power the next generation of the web -- is shaping up to be a nightmare for consumers who care about privacy and a goldmine for advertisers who don't. And it's Apple (AAPL)'s chosen system for the iPhone. Here's a primer on what HTML5 is, why you should be scared of it, and whether it's possible to opt-out of being tracked by the supercookies advertisers want to use on it.

The New York Times published a basic look at some of the issues involved with HTML5, but its article vastly understates the information-gathering power of HTML5 and the surreptitious way in which it works:

The new Web language and its additional features present more tracking opportunities because the technology uses a process in which large amounts of data can be collected and stored on the user's hard drive while online. Because of that process, advertisers and others could, experts say, see weeks or even months of personal data. That could include a user's location, time zone, photographs, text from blogs, shopping cart contents, e-mails and a history of the Web pages visited.
You can get some technical data on HTML5 from Wikipedia, which notes that one of HTML5's new features is an "offline storage database." Most uses are familiar with cookies, the little text files that advertisers use to remember who you are and when you last visited their web site. HTML5 makes those cookies much, much bigger. It will deposite 5MB-sized files on most browsers, and up to 10MB files on Internet Explorer. That's about the size of an MP3 song.

Worse, the files can't be deleted. The new supercookies store themselves in several different places on your machine, so even if you delete some of them they persist, or "respawn," resurrecting themselves from other parts of your machine. Several media companies have already been sued for reactivating supposedly deleted cookies. Those companies include MTV, ESPN, MySpace, Hulu, ABC, NBC, Quantcast and Scribd.

One advertising company that has already taken advantage of supercookies on Apple's Safari browser is Ringleader Digital:

Ringleader Digital uses cookies too, but goes a step further and makes use of Safari databases under iOS in order to ensure that users can be tracked -- forever.
Ringleader, whose clients include Travel Channel and the Partnership for a Drug-Free America -- makes a Safari cookie called RLDGUID that cannot be deleted, per Ars Technica:
When we deleted the RLDGUID databases on our phones, we found that it would instantly re-spawn with the same unique identifier we were previously assigned. It's pulling that ID from somewhere --likely a different Safari database generated by another Ringleader Digital partner site, or a traditional cookie working in conjunction with the database. We found that clearing cookies and the Safari databases still resulted in a recreation of the database with the same ID.
Ringleader says users can opt out for life if they want to, but that turns out to be difficult if you intend to do pretty much anything else with your iPhone:
Once implemented, the opt-out will be effective for the life of the device unless you install a new browser, update your existing browser, delete Ringleader's cookie (named "Mophap"), delete the content cache, or delete the RLD GUID database in the a.ringleaderdigital.com domain, in which case you will need to re-implement the opt-out utility in order to maintain your opt-out status.
Worse, Ringleader is not one of the companies that has signed up with the advertising industry's one-stop shopping behavioral tracking web page. (Even if it was, that system has holes. Although I praised the site last week for giving users a single place to go to in order to opt out of all tracking, I discovered that on a return visit today all those companies are back inside my machine. The site is therefore mostly useless.)

As P2Pnet points out, it's difficult to trust Ringleader and HTML5 if you cannot opt out of it. Ringleader's opt out requires you to accept a permanent Ringleader cookie identifying you as a non-cooperator:

The only way to 'opt-out' of them is to (a) realize what's going on; (b) go to Ringleader's website and have them place a unique identifier in the database they create on your device that indicates you've chosen to opt out of the tracking.
After demonstrating technical ingenuity and a willingness to (in effect) exploit HTML 5 and Safari Mobile, you just have to trust them to do the right thing after you opt-out.
Ringleader's respawning cookies are so pernicious they've even been condemned by the ad industry's interactive lobby group, the IAB.

iPhone users who care about their privacy should be especially fearful -- Apple is going full steam ahead in launching HTML5 on its web pages and mobile devices. As Apple cares greatly about its advertisers, and has many more of them than Android via the iTunes app store, HTML5 threatens to turn iPhone into a device whose main purpose is to spy on individual consumers, and to prevent those consumers from using their phones unless they agree to it.

(You know else wants in on HTML5? BNET owner CBS and, of course, the porn biz.)

Related:

Image by Flickr user rpongsaj, CC.
View CBS News In
CBS News App Open
Chrome Safari Continue