August 13, 2009

Developers should learn from the Palm Pre's privacy mistakes

If software vendors don't make their data-collection practices more transparent, regulators are liable to step in and do it for us

Is Palm watching you? If you bought one of its snazzy new Palm Pre phones, the answer is apparently yes -- and not just sometimes, either. According to Palm Pre hacker Joey Hess, the Pre's WebOS constantly logs usage data, including which applications you use, when, and for how long; it catalogs every app you have installed on your phone; it tracks the system state following application crashes; and it even tracks your location, obtained via GPS. All of these logs are sent back to Palm on a daily basis.

Could anyone even feign surprise that Palm Pre customers would be disturbed by this? It's one thing to agree to disclose certain personal information when you sign up for a service, but quite another to be made to disclose information all the time, every day, everywhere you go. To any rational person, that's the difference between a friend and a stalker.

[ See how the Palm Pre stacks up against the iPhone in InfoWorld's deathmatch. | Get the full scoop on next-gen mobile devices in InfoWorld's Mobile 2.0 Deep Dive PDF report. | Read our hands-on evaluation of the Palm Mojo SDK for Pre. ]

But there's no reason to single out Palm. As computing moves away from the desktop software paradigm toward Web-based services and cloud computing, a growing number of software vendors must confront similar issues. If Google's Chrome OS vision comes to pass and the bulk of computing moves from the desktop to the Web, virtually every application will become another opportunity to collect usage patterns, location, and other personally identifying user data. It's time software developers and vendors took an active role in addressing consumer concerns about data collection and privacy -- because if we don't, someone else might step in to do it for us.

Privacy policies aren't enough
Are there legitimate uses for the data Palm collects? Sure. Palm could use it to "customize your experience; troubleshoot and provide updates; ... resolve disputes; collect fees owed; detect and protect against error, fraud and criminal activity; comply with applicable law, regulations, legal processes or enforceable governmental requests," just like its privacy policy suggests.

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »
cmaurand 13-Aug-09 4:42am
I have to agree. The information palm collects is too much and, quite frankly, it doesn't have me wanting to purchase palm pre, which I was thinking about. I don't know if you've ever read a privacy statement, but they all say essentially the same thing (and this goes for HPAA statements, too.), "We value your privacy, but we're going to share your information with anyone who asks for it and to some who don't." Its making me want to jump off the grid, start using cash only and not have a cell phone. Palm wants TMI.
JeffSmithK 13-Aug-09 10:36am
One should not have to turn over their life just because they turned over some money for a product. What were these people thinking?!!! They are either going to kill demand or force heavey regulatory oversight. Either way is a problem for us all. Common sense people, common sense!
Wired-Guy 13-Aug-09 11:18am
Every smart phone user is, in fact, part of a focus group. Apple, Palm, Nokia, HP and soon, Dell all do it. They, and their partner wireless carriers track every call you make, every web site you surf to, they track where your phone physically is all the time, GPS or not - they know where the cell tower nearest to you is located. To minimize this intrusion, you can turn the phone off when you're not using it, you can turn off the GPS feature and in the case of the Palm Pre, you can turn off the automatic backup feature. Big Brother *is* watching you, and under current law, it's all legal.

Sign up to receive InfoWorld Resource Alerts

Subscribe to the Today's Headlines: First Look Newsletter

Find out what will be news for the day, with our first-thing-in-the-morning briefing.

©1994-2009 Infoworld, Inc.