Senator Sends Letter to Tim Cook Over Touch ID Privacy Concerns

NewImageSenator Al Franken (D-MN) has sent a letter to Apple CEO Tim Cook expressing concern over the new Touch ID fingerprint sensor built into the iPhone 5s, which went on sale earlier today.

In the letter (PDF), the Senator, Chairman of the Senate Judiciary Subcommittee on Privacy, Technology and the Law, says he is an iPhone owner and is concerned about the use of fingerprints to unlock the device.

It's clear to me that Apple has worked hard to secure this technology and implement it responsibly. The iPhone 5S reportedly stores fingerprint data locally "on the chip" and in an encrypted format. It also blocks third-party apps from accessing Touch ID. Yet important questions remain about how this technology works, Apple's future plans for this technology, and the legal protections that Apple will afford it. I should add that regardless of how carefully Apple implements fingerprint technology, this decision will surely pave the way for its peers and smaller competitors to adopt biometric technology, with varying protections for privacy.

Franken goes on to ask twelve separate questions of Cook, including:

- If it's possible to convert locally-stored fingerprint data into a format that can be used by third parties.

- If it's possible to extract and obtain fingerprint data from an iPhone 5s either remotely or with physical access to the device.

- What diagnostic information the iPhone 5s sends to Apple about the Touch ID system.

- Whether Apple considers fingerprint data to be the "subscriber information" or "electronic communication transactional records", the "contents" of communications, customer or subscriber records, or a "subscriber number or identity" as defined in the Stored Communications Act, or a "tangible thing" as defined in the USA PATRIOT Act.

The last group of questions relates to when and if Apple could be required to disclose fingerprint information to U.S. Government law enforcement agencies.


Apple, for its part, has posted an extensive knowledge base article about the security benefits of the Touch ID system, though it only discloses broad details about how the iPhone 5s stores fingerprint data, but nevertheless, it may answer some of the questions that Senator Franken asked:

Touch ID does not store any images of your fingerprint. It stores only a mathematical representation of your fingerprint. It isn't possible for your actual fingerprint image to be reverse-engineered from this mathematical representation. iPhone 5s also includes a new advanced security architecture called the Secure Enclave within the A7 chip, which was developed to protect passcode and fingerprint data. Fingerprint data is encrypted and protected with a key available only to the Secure Enclave. Fingerprint data is used only by the Secure Enclave to verify that your fingerprint matches the enrolled fingerprint data. The Secure Enclave is walled off from the rest of A7 and as well as the rest of iOS. Therefore, your fingerprint data is never accessed by iOS or other apps, never stored on Apple servers, and never backed up to iCloud or anywhere else. Only Touch ID uses it and it can't be used to match against other fingerprint databases.

Senator Franken gave Tim Cook and Apple thirty days to answer the questions and, though it is not a subpoena and Apple is not required to respond, the company is likely to cooperate.

This is not the first time that Senator Franken has interacted with Apple -- in 2011, he asked both Apple and Google to require clear privacy policies for apps sold on their app stores. He also introduced a bill to help protect customer location data.

Popular Stories

iPhone SE 4 Vertical Camera Feature

iPhone SE 4 Production Will Reportedly Begin Ramping Up in October

Tuesday July 23, 2024 2:00 pm PDT by
Following nearly two years of rumors about a fourth-generation iPhone SE, The Information today reported that Apple suppliers are finally planning to begin ramping up mass production of the device in October of this year. If accurate, that timeframe would mean that the next iPhone SE would not be announced alongside the iPhone 16 series in September, as expected. Instead, the report...
iPhone 17 Plus Feature

iPhone 17 Lineup Specs Detail Display Upgrade and New High-End Model

Monday July 22, 2024 4:33 am PDT by
Key details about the overall specifications of the iPhone 17 lineup have been shared by the leaker known as "Ice Universe," clarifying several important aspects of next year's devices. Reports in recent months have converged in agreement that Apple will discontinue the "Plus" iPhone model in 2025 while introducing an all-new iPhone 17 "Slim" model as an even more high-end option sitting...
Generic iPhone 17 Feature With Full Width Dynamic Island

Kuo: Ultra-Thin iPhone 17 to Feature A19 Chip, Single Rear Camera, Semi-Titanium Frame, and More

Wednesday July 24, 2024 9:06 am PDT by
Apple supply chain analyst Ming-Chi Kuo today shared alleged specifications for a new ultra-thin iPhone 17 model rumored to launch next year. Kuo expects the device to be equipped with a 6.6-inch display with a current-size Dynamic Island, a standard A19 chip rather than an A19 Pro chip, a single rear camera, and an Apple-designed 5G chip. He also expects the device to have a...
iPhone 16 Pro Sizes Feature

iPhone 16 Series Is Less Than Two Months Away: Everything We Know

Thursday July 25, 2024 5:43 am PDT by
Apple typically releases its new iPhone series around mid-September, which means we are about two months out from the launch of the iPhone 16. Like the iPhone 15 series, this year's lineup is expected to stick with four models – iPhone 16, iPhone 16 Plus, iPhone 16 Pro, and iPhone 16 Pro Max – although there are plenty of design differences and new features to take into account. To bring ...
icloud private relay outage

iCloud Private Relay Experiencing Outage

Thursday July 25, 2024 3:18 pm PDT by
Apple’s iCloud Private Relay service is down for some users, according to Apple’s System Status page. Apple says that the iCloud Private Relay service may be slow or unavailable. The outage started at 2:34 p.m. Eastern Time, but it does not appear to be affecting all iCloud users. Some impacted users are unable to browse the web without turning iCloud Private Relay off, while others are...

Top Rated Comments

Superdrive Avatar
142 months ago
What he really meant: "What are you collecting and how can we get our hands on it?"
Score: 72 Votes (Like | Disagree)
MacIke Avatar
142 months ago
Nsa

I am far more concerned about the NSA and the issue of spying then I am of some company. A company has to actually respond to the customer. Whereas the government does not give a rats ass.
Score: 45 Votes (Like | Disagree)
HiVolt Avatar
142 months ago
PC laptops have had fingerprint sensors for years... Why isn't he writing Lenovo, Dell, HP?

This guy is just "concerned" to get his name in the news with a big name company like Apple and the new phone release, makes it look like he cares for his people...
Score: 37 Votes (Like | Disagree)
k1121j Avatar
142 months ago
Give me a break

Does this guy want to look good or something. If i am not mistaken this is not the first consumer product with fingerprint technology ( example all those laptops out there come to mind) and as far as i can tell Apple has gone further to secure your identity where there device. SOOO get off there back and be logical you silly senator
Score: 37 Votes (Like | Disagree)
croooow Avatar
142 months ago




Yeah, lets take this guy seriously...
Score: 34 Votes (Like | Disagree)
notabadname Avatar
142 months ago
But it's ok, it's Apple. If this was Google collecting this information, you guys would be up in arms.

Well, since Apple has made clear it is not collecting the data, and it resides only on the phone's chipset, your point is sort of irrelevant.
Score: 28 Votes (Like | Disagree)