Passcode-Collecting App Pulled From App Store [Updated] - MacRumors
Skip to Content

Passcode-Collecting App Pulled From App Store [Updated]

by

Earlier this week, iOS developer Daniel Amitay published a report examining trends in passcodes chosen by users of his Big Brother Camera Security application. Amitay had anonymously collected over 200,000 passcodes used on his app and offered the data up as a proxy for actual iPhone passcode usage data based on the similarity of the input system style and functionality.

big brother camera security enter passcode
Amitay now reports that his application has been pulled from the App Store by Apple, although he is unsure at this time whether the removal was due to publication of the data or his admission of collecting it in the first place.

As of today at 4:58pm EST, Big Brother has been removed from the App Store. I'm certainly not happy about it, but considering the concerns a few people have expressed regarding the transfer of data from app to my server, it is understandable.

I think I should clarify exactly what data I was referring to, and how I was obtaining it. First, these passcodes are those that are input into Big Brother, not the actual iPhone lockscreen passcodes. Second, when the app sends this data to my server, it is literally sending only that number (e.g. "1234") and nothing else. I have no way of identifying any user or device whatsoever.

Amitay points to Apple's iTunes licensing agreement in support of his belief that he can collect such information, noting that he had planned on using the data collected to generate a list of common passcodes that would offer a warning of the codes being too obvious if they were chosen by a user. Consequently, it is unclear whether it is the collection itself or the publication of it that raised Apple's ire.

Amitay is currently reaching out to Apple to address the issue and have Big Brother Camera Security returned to the App Store.

Update: Amitay has updated his post to note that he has received a response from Apple relaying that his application was pulled for "surreptitiously harvesting user passwords". He has submitted an updated version of the application omitting the passcode collection capabilities and has appealed Apple's decision on the basis of the data being specific to the app, anonymized, and used for the purposes of improving the application.

Top Rated Comments

199 months ago
This developer has done nothing wrong, besides show the stupidity of users who use passcodes such as these. The unsolicited collection of data is something that happens everyday. Whenever you shop at WalMart, they record your credit card number and what you bought so they can refund you if need be. BUT they can easily bring up a purchase history and work out what your shopping style is, what you like to buy, what kinds of thing you buy. That's an invasion of privacy to a degree, but do you care?

The HUGE difference here is the developer can't tie up passcodes to individuals. What he wanted to do was look at the bigger picture. Apple published that they've sold x million iPads. OMG My iPad is in that statistics! That's MY data THEY HAVE NO RIGHT! See how stupid that is?

Information is taken from you all the time, whether or not you know it, and for most purposes it's used for seeing trends in large datasets, not to target you personally. Until your personal privacy is breached there's no need to cry. Apple are bending to consumer pressure because of a large volume of complaints they've probably received about the App.
Score: 8 Votes (Like | Disagree)
199 months ago
What is the big advantage of Apple's curated App Store? Oh right, that Apple checks all apps for such things before making them available to the public.

As much as I don't approve of what this developer did, I also fear that there are thousands of apps out there, installed on millions of iOS devices, that send much more private data than just a passcode for the lock screen, unasked.

Apple gets 30% of the revenue, they could be a bit more thorough when testing apps...

That's just not realistically possible. For a start, you'd need to packet sniff all wi-fi packets and trawl through the data looking for something that looked like a 4 digit code in this case. Moreover, the minute Apple started doing this, any developer with malicious intent would immediately switch to sending all data over SSL/TLS. When the data is encrypted, the app could be sending anything and there would be no way to know.

Apple are doing the right thing - their API's heavily limit the damage a rogue developer can do but to try to go any further would just be a waste of everybody's time.
Score: 5 Votes (Like | Disagree)
42streetsdown Avatar
199 months ago
This developer has done nothing wrong, besides show the stupidity of users who use passcodes such as these. The unsolicited collection of data is something that happens everyday. Whenever you shop at WalMart, they record your credit card number and what you bought so they can refund you if need be. BUT they can easily bring up a purchase history and work out what your shopping style is, what you like to buy, what kinds of thing you buy. That's an invasion of privacy to a degree, but do you care?

The HUGE difference here is the developer can't tie up passcodes to individuals. What he wanted to do was look at the bigger picture. Apple published that they've sold x million iPads. OMG My iPad is in that statistics! That's MY data THEY HAVE NO RIGHT! See how stupid that is?

Information is taken from you all the time, whether or not you know it, and for most purposes it's used for seeing trends in large datasets, not to target you personally. Until your personal privacy is breached there's no need to cry. Apple are bending to consumer pressure because of a large volume of complaints they've probably received about the App.

People will always make big deals about these 'privacy' issues. It's the same thing as the whole location cache. People'll freak out because they think that somehow they're somehow special and that their info matters.

Should this dev have told his users about this study of his prior to do it? probably. Did it hurt anyone at all? NO
Score: 5 Votes (Like | Disagree)
jclardy Avatar
199 months ago
I don't think anonymous data collection should be forbidden, but when collecting something that could be "personal" information it should be.

In this case it is a users PIN code. While most were probably meaningless, some people may have used the same code to unlock their phone, the same code they use for their bank card or some other important number.

And the issue for me isn't so much that he collected it, it is that the code was probably sent in plaintext over a normal HTTP connection. So if someone was around you with a packet sniffer they could easily grab your unlock code. Of course the chances of this happening are essentially zero (A person must be sniffing the wifi that you are on, you must be using this app, and you must be setting your unlock code) it is still something you probably shouldnt do.

I'm fine with developers collecting simple anonymous data like "how many times did I open this app" or something along those lines, but I'd rather not have my device broadcasting security codes or passwords.
Score: 4 Votes (Like | Disagree)
199 months ago
You do realise that app developers are allowed to collect data from people using their apps as long as its anonymous? And the user agreement that we as users sign up to could be classed as letting us know that this can happen in any app. So technically i think he's still working within the EULA. I'm not saying i agree with what he did, but theres no need to flame the guy and call for life time bans etc. if he genuinely wanted to use the data to improve his application by stopping people using common passcodes. I'm sure analysis of passwords to persuade people to use less common passwords is/has been a common thing on the internet.

Also IMO it's not like he set out to trick people into using the same phone lock passcode for his app,(maybe i'm wrong and there were ulterior motives to it). But really, we shouldn't be using the same passwords for things, do you use the same pin code for your atm as your phone, or the same password for online banking and your macroumous login?

Edit: ok re-read the article and he did say that because of the similarity in the code screen he thought it may correlate with real codes, but still from the EULA apple does give the developers the right to do it and we still blindly accept the agreement and really he can't do anything with the data to harm anyone, and i think it helps to bring to light the importance of not using easy to guess common passwords (at the read the EULAs we accept)
Score: 4 Votes (Like | Disagree)
199 months ago
This developer has done nothing wrong, besides show the stupidity of users who use passcodes such as these. The unsolicited collection of data is something that happens everyday. Whenever you shop at WalMart, they record your credit card number and what you bought so they can refund you if need be. BUT they can easily bring up a purchase history and work out what your shopping style is, what you like to buy, what kinds of thing you buy. That's an invasion of privacy to a degree, but do you care?

The HUGE difference here is the developer can't tie up passcodes to individuals. What he wanted to do was look at the bigger picture. Apple published that they've sold x million iPads. OMG My iPad is in that statistics! That's MY data THEY HAVE NO RIGHT! See how stupid that is?

Information is taken from you all the time, whether or not you know it, and for most purposes it's used for seeing trends in large datasets, not to target you personally. Until your personal privacy is breached there's no need to cry. Apple are bending to consumer pressure because of a large volume of complaints they've probably received about the App.
Agreed. It is probably the same stupid users that have 0000 or 1234 as their passcodes that are all up in arms about OMG DEY STEELIN MA INFOS! You get your information stolen every day, but since its not brought to your attention in an article, you don't care? I get so many Amazon emails "recommending similar products" that I would never use that it borders on spam. How do they know which products are similar? Oh noes! Shut down Amazon!
Score: 3 Votes (Like | Disagree)

Popular Stories

iphone 18 pro max prepare

iPhone 18 Pro Max Requires 'Prepare to Ship' Battery Drain Before Shipping

Friday September 18, 2026 4:27 pm PDT by
The iPhone 18 Pro Max has a battery capacity over 20 watt-hours, which means there are additional shipping requirements. If an iPhone 18 Pro Max needs to be shipped somewhere, its maximum battery capacity has to be limited through firmware. According to Apple, the iPhone 18 Pro Max uses an "innovative battery-firmware solution" that limits battery capacity to below 20Wh between when the...
imac video apple feature

Apple Releasing Two New Macs Next Week

Friday September 18, 2026 10:07 am PDT by
Last month, Apple announced new Mac mini and Mac Studio models, and the computers are finally set to launch this coming Tuesday, September 22. The new Mac mini is available with M6 and M5 Pro chip options, while the new Mac Studio can be configured with M5 Max or M5 Ultra chips. To learn more, read our coverage:Apple Announces New Mac Mini With M6 and M5 Pro Chips and More Apple Unveils ...
iphone duo weather

Apple Exec Says 'Hold Us Accountable' on iPhone Duo Crease

Friday September 18, 2026 9:51 pm PDT by
Apple hardware engineering VP Tom Marieb spoke with TechRadar and shared some candid thoughts about Apple's upcoming iPhone Duo. The iPhone Duo uses a matte nano-texture display, which is meant to cut down on glare and minimize the visibility of the crease. When asked if the iPhone Duo's crease would be more visible over time, as that's what tends to happen on other foldables, Marieb said...
Latest Stories
OWC's Best Mac Accessories Are on Sale Just for MacRumors Readers
OWC's Best Mac Accessories Are on Sale Just for MacRumors Readers
1 hour ago
New Mac Studio's Biggest Upgrade Isn't the M5 Ultra Chip, Review Says
New Mac Studio's Biggest Upgrade Isn't the M5 Ultra Chip, Review Says
1 hour ago
How to Force Quit Apple Watch Apps in watchOS 27
How to Force Quit Apple Watch Apps in watchOS 27
2 hours ago
New Mac Mini and Mac Studio Launch Tomorrow
New Mac Mini and Mac Studio Launch Tomorrow
2 hours ago
Apple Watch Series 12 and Ultra 4 May Have Hidden Flash Storage
Apple Watch Series 12 and Ultra 4 May Have Hidden Flash Storage
2 hours ago
iPhone 20 Pro Display Sizes Leak Ahead of 2027 Launch
iPhone 20 Pro Display Sizes Leak Ahead of 2027 Launch
4 hours ago
Apple Watch Series 12 and Ultra 4 Owners Report Unexpected Reboots
Apple Watch Series 12 and Ultra 4 Owners Report Unexpected Reboots
6 hours ago
iFixit Shares iPhone 18 Pro Teardown With Inside Look at New Features
iFixit Shares iPhone 18 Pro Teardown With Inside Look at New Features
11 hours ago
Apple Fitness+ Layoffs Reported Ahead of Potential 'Major' Changes
Apple Fitness+ Layoffs Reported Ahead of Potential 'Major' Changes
12 hours ago
A Shorter Apple Pencil Was Supposed to Launch Alongside iPhone Duo
A Shorter Apple Pencil Was Supposed to Launch Alongside iPhone Duo
12 hours ago
Siri AI Settlement Website Now Live: Apple to Pay Some iPhone Owners
Siri AI Settlement Website Now Live: Apple to Pay Some iPhone Owners
13 hours ago
M6 Pro Chip Result on Geekbench is Likely Fake
M6 Pro Chip Result on Geekbench is Likely Fake
2 days ago
Apple Watch Ultra 4 Sees First Discount After Launch, Now $779.99 on Amazon
Apple Watch Ultra 4 Sees First Discount After Launch, Now $779.99 on Amazon
2 days ago
Top Stories: iOS 27 and macOS Golden Gate Out Now, Siri AI Waitlist, and More
Top Stories: iOS 27 and macOS Golden Gate Out Now, Siri AI Waitlist, and More
2 days ago
Apple Exec Says 'Hold Us Accountable' on iPhone Duo Crease
Apple Exec Says 'Hold Us Accountable' on iPhone Duo Crease
2 days ago
iPhone 18 Pro Max Requires 'Prepare to Ship' Battery Drain Before Shipping
iPhone 18 Pro Max Requires 'Prepare to Ship' Battery Drain Before Shipping
3 days ago
Hands-On With the Apple Watch Series 12
Hands-On With the Apple Watch Series 12
3 days ago
M5 Ultra and M6 Chip Benchmark Results Reveal Graphics Performance
M5 Ultra and M6 Chip Benchmark Results Reveal Graphics Performance
3 days ago
iPhone 18 Pro Max in U.S. Has Qualcomm's Snapdragon X80 Modem
iPhone 18 Pro Max in U.S. Has Qualcomm's Snapdragon X80 Modem
3 days ago
Apple Releases Xcode 27.1 Beta With iPhone Duo Support
Apple Releases Xcode 27.1 Beta With iPhone Duo Support
3 days ago
Apple Watch Series 12 vs. Ultra 4 Buyer's Guide
Apple Watch Series 12 vs. Ultra 4 Buyer's Guide
3 days ago
MacRumors Giveaway: Win an iPhone Duo From iMazing
MacRumors Giveaway: Win an iPhone Duo From iMazing
3 days ago
'Shop Different': Apple Retail Pioneer Ron Johnson Shares the Inside Story
'Shop Different': Apple Retail Pioneer Ron Johnson Shares the Inside Story
3 days ago
Apple Teams Up With ROSÉ for iPhone 18 Pro Camera Ad
Apple Teams Up With ROSÉ for iPhone 18 Pro Camera Ad
3 days ago
The MacRumors Show: Is the iPhone Duo Actually Worth It?
The MacRumors Show: Is the iPhone Duo Actually Worth It?
3 days ago
Apple Designers Explain the Thinking Behind iPhone Duo
Apple Designers Explain the Thinking Behind iPhone Duo
3 days ago
Are iPhone 17 Pro Cases Compatible With iPhone 18 Pro? Here's What Apple Says
Are iPhone 17 Pro Cases Compatible With iPhone 18 Pro? Here's What Apple Says
3 days ago
Apple Supplier Subsidiary Considering U.S. Flash Memory Factory
Apple Supplier Subsidiary Considering U.S. Flash Memory Factory
3 days ago
Apple Launch Day Deals on iPhone 18 Pro, AirPods 5, Apple Watch Series 12, and More
Apple Launch Day Deals on iPhone 18 Pro, AirPods 5, Apple Watch Series 12, and More
3 days ago
iPhone 18 Pro Teardown Reveals How Apple Shrunk the Dynamic Island
iPhone 18 Pro Teardown Reveals How Apple Shrunk the Dynamic Island
3 days ago