Opt-Out missing for Siri/Dictation Service access to contacts

Originator:m.hanauska
Number:rdar://19530240 Date Originated:20-Jan-2015
Status:Open Resolved:
Product:iOS Product Version:8
Classification:Security Reproducible:Always
 
Summary:
When using Siri or Dictation Services, you can opt out that your geo location is sent with every request but you cannot opt out that your address book data is being sent. Apple says that this is no problem as data is stored anonymously with a random ID and not linked to my Apple ID, just as my recorded speech data. However, when my address book data is sent, that data is NOT ANONYMOUS AT ALL. 

Even if just my first name and nick name are sent (not my last name), how hard is it to find out who I am if also the names of my mother and father are being sent as well and their relationship status (the fact that these two people are actually my parents)? Also if my location is included, it is very easy to find out where I live and where I work, and that information together with my first name is already all that is required to reveal my identity. So speaking about anonymous data here is nonsense.

Actually the fact that my geo location is sent is less a privacy concern to me than the fact that my name, my contacts and my family information is transferred to Apple. I'd rather allow access to my geo location than to my address book, yet you allow to opt out geo location but not to opt out address book access.

And as long as my speech recordings being sent to Apple cannot be linked to my person, that data is somewhat protected, but as soon as it is possible to link that data with me, it's also possible to pretty much invade my privacy as a whole.

Steps to Reproduce:
1. Open Settings app
2. Choose Privacy
3. Choose Contacts

Expected Results:
An entry for Siri and Dictation.

Actual Results:
No entry for Siri and Dictation.

Version:
iOS 8.1

Notes:
The funny thing is, you say you need that data to recognize when I address a person from my address book, but when I disable Siri altogether, I get voice dial, which does __exactly that__, it identifies people from my address book, directly on my phone, no need to send that data to any server.

Comments


Please note: Reports posted here will not necessarily be seen by Apple. All problems should be submitted at bugreport.apple.com before they are posted here. Please only post information for Radars that you have filed yourself, and please do not include Apple confidential information in your posts. Thank you!