EXCLUSIVE: Apple engineer says he was fired after refusing to send customer device IDs to AT&T

Its an article being viralled around now. First of all i’m not defending Apple, nor shitting on Apple, I’m indifferent. I’m also not a native English speaker and reading the article theres a few weird, strange things being cited like

A 16-year employee

Whats the minimum age to be employed in the us?

His version of the story begins three years earlier

He worked at Apple since he was 13?

Boardman was an Enterprise Systems Engineer.

Doesn’t sound like a job a 13yo could have, especially at Apple. Fancy sounded is an understatement.

Thoughts? My head hurts trying to understand everything there.

2 Likes
  1. Your Apple ID is tied to your phone’s hardware. Changing sim cards does not obfuscate (hide) your phone’s identity.
  2. Apple shares your PII (Personable Identifible Info) with 3-rd parties without your consent.

THe article seems to be a hit-piece on this unfortunate engineer. Glossing over point 1 and point2.

conclusion: dump your iPhone immediately…

2 Likes

It means he was at the company for 16 years. If it were his age, it would be said as ‘16-year-old.’

4 Likes

Holy shet, thank you. That made perfect sense!

16-year employee is a bit of strange way to write it, so it makes sense it was confusing. It’s a similar idea to a three hour tour. I swear I’m not that old though.

I would write that as “Toby Boardman, an employee of 16 years” instead, but they must have wanted a punchier subtitle.

I don’t know how many times I have to repeat this, but it’s important to know a company’s priorities when picking a product or service to use.

GrapheneOS cares about your privacy above all and builds strong security defenses to protect it.

Meanwhile, Apple cares about shareholder value and shaking hands with politicians or other companies that would benefit their corpo.

Apple is not your ally and never will be.

2 Likes

Marketing. That’s Apple.

Profit. That’s Apple.

Shareholders. That’s Apple.

This is a big fat nothing burger.

Of course a carrier needs access to an IMEI. It’s needed for a dozen legitimate reasons including security/privacy benefits to the customer. The top two use cases are identifying stolen devices on the network and preventing/detecting sim swap attacks.

Does anyone here honestly think your carrier doesn’t have your IMEI or need it to provide services you are paying for?

Also the guy behind this lawsuit is the living definition of the 90/10 rule. Yikes.

Why do the carriers need the IMEIs of devices already sold to customers (presumably, if the engineer is saying they needed a release from the customers to send them, which wouldn’t make sense if this were some kind of presale process) from Apple and sent over email?

They will be provided the IMEI by the customer when the customer connects the device to their network.

Something is definitely at least a bit off here, assuming those basic facts of the situation are true.

1 Like

What’s the 90/10 rule in this context?

IMEI spoofing and theft tracking, maybe. I’m not sure if they needed a release form or notification before sending it. Email isn’t the right way to send it, in any case.

I bet apple is also freaked out about the disability aspect. I always had employers be defensive about that. I would expect to not get a job offer if I disclosed in advance. Eventually they tend to get I am not going to settle for anything less than my legal rights, nor will I ask for anything more*, but in a situation like this it can be hard to get any dialogue going.

*Meaning, if I can’t do the job well then I expect to be treated like any other employee, while any accommodations should not come with, from their perspective, the potential to jeopardize safety or results.

First I’m not sure the details are really known. For instance, the supposed “insecure email” transmission of IMEI isn’t actually documented in the lawsuit. If it is a PGP encrypted email or even just TLS between Apple and AT&T that could be fine. Maybe the request was from email but another method sent the data. The fact is no actual evidence was presented documenting an improper sending of data.

Secondly there are plenty of reasons the carrier needs IMEI. Maybe a customer is complaining that their new SIM isn’t working and it’s needed to troubleshoot. Perhaps John Smith lives in Atlanta but suddenly a new device is using his SIM in Chicago, was he sim swapped/cloned? Or a slew of new devices are added to the network unexpectedly, are they stolen?

I’m sure the professionals running a carrier could add dozens of examples. The uncomfortable fact is that using a cellular device is never really anonymous because of how the basic infrastructure works. It can be private as far as data content goes but meta data is unavoidable.

When leading and managing people, 90% of your time will be consumed dealing with 10% of your subordinates. Most people are honest and hard working who just need some direction. But some people are just difficult and cause problems no matter where they are. The guy behind this lawsuit sounds like that.

You’re really missing the point. If this is standard data sharing then email is not at all the appropriate means of doing so, if for no other reason than that would be absurd to manage. If it is only in special cases for a handful of IMEIs, what context requires it and why is Apple just complying with those requests by private companies?

The headline is about IMEI sharing between Apple and AT&T.

A mentally unstable person has claimed that data was shared via email. There is no evidence to back this claim. Posters in this thread are assuming the claim is true because it confirms their priors. It is intellectual laziness in the name of dunking on a company they don’t like.

From the article:

No court has found that Apple or AT&T mishandled customer information, that the requested releases were legally required, or that Apple fired Boardman because he objected. The public file does not contain the disputed emails, the report Boardman says he made, the internal privacy policy he relied upon or an example of a customer whose data was shared. Apple’s answer does not specifically address the IMEI allegation.

Source: RuntimeWireEXCLUSIVE: Apple engineer says he was fired after refusing to send customer device IDs to AT&T - RuntimeWire

Like I said, this is a nothing burger.

PGP is pretty rare and there’s no way to ensure that the TLS will be encrypted end to end. It can be decrypted during transit for legitimate purposes. There is also the whole issue of it sitting in two servers, accessible by two people’s email accounts, and how that is handled. Realistically, they would be unlikely to use email for any reason other than convenience.

I agree we don’t have all the facts, but email is not the answer for sharing personal data.