Rendered at 14:40:12 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
wmf 11 hours ago [-]
This guy is going to lose. If a company is violating no laws and your manager tells you to drop it, you can either drop it or quit. You don't get to choose how to interpret company policy.
Tyrubias 11 hours ago [-]
I agree this engineer will probably lose the case because Apple has better lawyers, but I believe your underlying argument to be incorrect. If your manager asks you to violate company policy, then the correct response is to not violate company policy and instead contact HR/legal. Otherwise, saying “my manager made me do it” will not save you if heads start to roll. This applies to both policies that are strictly internal as well as policies that are due to an underlying law. When it comes down to it, neither you nor your manager actually interpret laws or internal policies.
wmf 11 hours ago [-]
The article says he did contact legal and I guess they declined to intervene.
mixdup 11 hours ago [-]
Yeah, this guy picked a weird thing to take a stand on. Apple corporate policy is not enforceable by state courts. IMEI to serial mapping is not a protected data class in any way in the US. I'm actually confused that this had to be handled by a person, one would assume that AT&T would've just had access to this data as a carrier.
mike_d 11 hours ago [-]
At any large employer you sign an agreement to follow the employee handbook and internal policies. They all say the same thing: don't violate the policies even if directed to by your manager.
In this case Apple's legal department had identified the serials and IMEIs as PII.
This is why the case is in civil court and not criminal (because Apple didn't violate any "laws" as you claim). It is a contract dispute.
otterley 9 hours ago [-]
Boardman notified Apple’s legal team. At that point it was their decision to make. If they had told him to stop, that’d be one thing. But they didn’t, and it wasn’t up to Boardman to interpret the policy differently.
10 hours ago [-]
applfanboysbgon 11 hours ago [-]
There's a non-zero chance that Apple might settle if this gets sufficient media coverage, rather than letting it drag on for years making headlines and causing PR damage that exceeds what it would take to buy him off. Even if not illegal, this is surely not the kind of headline Apple wants to be in the news for.
wmf 11 hours ago [-]
Yeah, it's almost always better to settle than to go to court. But he's going to get less than he's asking for. And I bet he really wants an apology which he won't get.
loeg 11 hours ago [-]
That sounds better for him than dropping it?
codedokode 11 hours ago [-]
This is why you should use open-source firmware where there is no registration and customer IDs. Also, the software should allow overwrite IMEI to a random value daily.
> Boardman believed the meeting would finally address both issues.
> Apple fired him the next day.
This is a reminder that being honest with a company doesn't benefit you.
dredmorbius 11 minutes ago [-]
The device IMEI is used to establish account identity for cellular service. It's intrinsic to functioning as a mobile device.
IMEI is not GAID (Google Ad ID) or IDFA (Identifier for Advertisers, for iOS devices), which can be changed. Google Android allows users to change GAID (in a rather cumbersome process), some privacy-conscious Android alternatives automate this on a regular basis AFAIU.
IMEI doesn't function like a MAC address, which can also be changed with relatively little concern (though it's helpful to present the same MAC to the same network on repeated connects, particularly if that network limits access to known MAC addresses, a ... rather weak form of security).
Moreover, IMEIs are useful in limiting the usefulness of stolen devices, as the IMEI can be added to a blocklist by carriers to prevent their use on networks. There's been (unsuccessful to date) legislation proposed in the US to ban IMEI modification entirely. In practice it is possible to change IMEIs, but that would effectively result in the device being unrecognised by the carrier, and new service under the new IMEI would have to be established. This isn't something you could do easily while continuing to use the same number (absent, say, number portability ... which would defeat much of the identity skirting), though it might fit some use cases.
IMEI is largely present only on phones with SIM or eSIM capabilities, but is independent of the SIM itself. Changing the SIM/eSIM will NOT change the IMEI.
More generally: it is hard to make cellular device use private, given that effective identity leaks occur through so many channels. Location, proximity to other devices, patterns of use, patterns of contacts, billing information, associated phone numbers, other account contacts, and the like. Much as I'd prefer otherwise, a given phone probably maps pretty closely with an individual or small group (family, household, business location / work crew, etc.). That's pretty intrinsic to how the system functions.
Securing data on the device may be more tractable, but limits exist there too.
scheme271 7 hours ago [-]
How would that work? Wouldn't changing the IMEI regularly either get your phone blacklisted or it may not even get service due to the IMEI not being in your cell provider's system?
noman-land 7 hours ago [-]
Any recs for such firmware (that randomizes IMEI)?
dredmorbius 9 minutes ago [-]
Linked from Wikipedia's IMEI article, though apparently not a particularly solid source:
The apparent takeaway is that Apple devices on AT&T have reduced privacy.
This may change, obviously. Likely for the worse.
tdeck 11 hours ago [-]
I have to say this sounds like an extremely believable form of shoddy PII stewardship.
radium3d 11 hours ago [-]
AT&T looking for more user data to leak to everyone? Already did the SSNs
nissa-seru 9 hours ago [-]
I do not have enough pangram credits (free) to check the whole article, but running significant parts of it through, I am getting 100% AI generated.
This is not an indictment - it is merely an observation. (to mimic gpt-style for a moment)
hilbert42 11 hours ago [-]
There are two laws missing that allow such privacy violations to occur.
First is strong and enforceable law that makes it unlawful to violate one's privacy. The second is to prosecute violators directly—that is, employees cannot hide behind corporate walls and allow the corporate entity to take the blame.
Irrespective of what employers demand, employees have a responsibility to obey the law. Risk of individual employees being chucked in the slammer would change corporate culture overnight.
Fining corporations alone is a waste of time, they see such fines as the cost of doing business, losing one's freedom for an individual is another matter altogether. Employees must be frightened of the consequences of violating the law or the practice will continue.
rileymat2 10 hours ago [-]
The main federal laws that are missing is a formal definition of what data you own and expect privacy and what data on you the company owns. In this case it is specified by contract which may or may not have been breached not law.
opengrass 4 hours ago [-]
What a drama queen, guy never even had to step into the office.
burnt-resistor 4 hours ago [-]
Ethical consistency is more important than any job. Without this, one may become a Palantir engineer... completely lacking in morals and enabling real world evil.
sigmonsays 11 hours ago [-]
Link to non paywall version?
ryanmerket 11 hours ago [-]
we don't monetize yet, it's just email
gortok 11 hours ago [-]
But we don’t want to have to give you our email.
ryanmerket 11 hours ago [-]
all good, i removed it
9 hours ago [-]
mohamedkoubaa 11 hours ago [-]
[flagged]
m3kw9 11 hours ago [-]
[flagged]
xprnio 11 hours ago [-]
HackerNews will always be here to welcome you
exac 11 hours ago [-]
Think Different™ now means selling out you.
BLKNSLVR 11 hours ago [-]
We have patented Think Different™ to mean "think the same as every other money grubber in the business".
They're not words anymore, they're newspeak SEO soundbytes.
In this case Apple's legal department had identified the serials and IMEIs as PII.
This is why the case is in civil court and not criminal (because Apple didn't violate any "laws" as you claim). It is a contract dispute.
> Boardman believed the meeting would finally address both issues.
> Apple fired him the next day.
This is a reminder that being honest with a company doesn't benefit you.
IMEI is not GAID (Google Ad ID) or IDFA (Identifier for Advertisers, for iOS devices), which can be changed. Google Android allows users to change GAID (in a rather cumbersome process), some privacy-conscious Android alternatives automate this on a regular basis AFAIU.
IMEI doesn't function like a MAC address, which can also be changed with relatively little concern (though it's helpful to present the same MAC to the same network on repeated connects, particularly if that network limits access to known MAC addresses, a ... rather weak form of security).
Moreover, IMEIs are useful in limiting the usefulness of stolen devices, as the IMEI can be added to a blocklist by carriers to prevent their use on networks. There's been (unsuccessful to date) legislation proposed in the US to ban IMEI modification entirely. In practice it is possible to change IMEIs, but that would effectively result in the device being unrecognised by the carrier, and new service under the new IMEI would have to be established. This isn't something you could do easily while continuing to use the same number (absent, say, number portability ... which would defeat much of the identity skirting), though it might fit some use cases.
IMEI is largely present only on phones with SIM or eSIM capabilities, but is independent of the SIM itself. Changing the SIM/eSIM will NOT change the IMEI.
<https://en.wikipedia.org/wiki/International_Mobile_Equipment...>
More generally: it is hard to make cellular device use private, given that effective identity leaks occur through so many channels. Location, proximity to other devices, patterns of use, patterns of contacts, billing information, associated phone numbers, other account contacts, and the like. Much as I'd prefer otherwise, a given phone probably maps pretty closely with an individual or small group (family, household, business location / work crew, etc.). That's pretty intrinsic to how the system functions.
Securing data on the device may be more tractable, but limits exist there too.
<https://www.imeichanger.net/>
This may change, obviously. Likely for the worse.
This is not an indictment - it is merely an observation. (to mimic gpt-style for a moment)
First is strong and enforceable law that makes it unlawful to violate one's privacy. The second is to prosecute violators directly—that is, employees cannot hide behind corporate walls and allow the corporate entity to take the blame.
Irrespective of what employers demand, employees have a responsibility to obey the law. Risk of individual employees being chucked in the slammer would change corporate culture overnight.
Fining corporations alone is a waste of time, they see such fines as the cost of doing business, losing one's freedom for an individual is another matter altogether. Employees must be frightened of the consequences of violating the law or the practice will continue.
They're not words anymore, they're newspeak SEO soundbytes.