Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

MacRumors

macrumors bot
Original poster
Apr 12, 2001
64,884
33,048



Last month, Apple released iOS 12.2 in beta with several new features, including the Apple News app in Canada, a redesigned TV remote in Control Center, support for adding HomeKit-enabled TVs in the Home app, and more.

The upcoming software update also introduces a new Motion & Orientation Access toggle under Settings > Safari > Privacy & Security. Toggled off by default, this new setting must be turned on in order for websites to display features that rely on motion data from the gyroscope and accelerometer in the iPhone, iPad, and iPod touch.

safari-motion-access-2-800x516.jpg

To test this, we loaded the What Web Can Do Today website on an iPhone running the first beta of iOS 12.2. With the Motion & Orientation Access setting toggled on, the page shows real-time accelerometer and gyroscope data from the iPhone. With the setting toggled off, no motion data is shown.

Another example is Apple's motion-based iPhone experience site. This page normally allows you to tilt your actual iPhone to swivel the iPhone XS Max on the screen with tech specs. With Motion & Orientation Access toggled off, however, only a static image of the iPhone XS Max is shown without tech specs.

safari-motion-access-1-800x779.jpg

This privacy-focused change could be in response to a WIRED report last year that claimed thousands of websites have unmitigated access to motion, orientation, proximity, and light sensor data on mobile devices. Software engineer Felix Krause also filed a radar and notified Apple's security team about this matter in 2017.

As noted by Digiday, the setting could have implications for AR/VR advertising:
For example, Samsung's "Samsung Within" web-based interactive experience, developed by R/GA to promote the hardware brand's legacy and its Galaxy Note 9 phone, uses the accelerometer to let people explore the night sky.

"It's definitely going to break things," said Kai Tier, executive technology director at R/GA.
These AR/VR experiences may have to rely on fallback versions that people can navigate with swipe gestures instead, but this largely defeats the purpose of motion-based, interactive campaigns.

It's quite possible Apple could tweak how this feature works in time for the public release of iOS 12.2. Perhaps the setting will be toggled on by default in a subsequent beta, for example, or Safari could prompt users for permission to access motion data when necessary as it does with location data.

Article Link: Apple to Limit Accelerometer and Gyroscope Access in Safari on iOS 12.2 for Privacy Reasons
 

brinary001

Suspended
Sep 4, 2012
991
1,134
Midwest, USA
Not sure how much this would preserve privacy, but at the same time I can't imagine accelerometer data is very largely used in mobile web dev in the first place.

Sounds more just like security theatre being put on by Apple, but if anyone out there knows something I don't, by all means feel free to enlighten me.
 

aottke

macrumors newbie
May 18, 2010
21
28
Interesting. The limitations to interactive ad or experiential campaigns would be frustrating for many companies that have things in the works. But this would provide another potential opportunity for Apple, which they really should look into: an internally-hosted and -approved ad platform. Apple should offer a way to have interactive ads that rely on iOS device information to the company for review and eventual hosting once approved. This way, they keep control of where that data goes (I think many trust Apple more than any other company to keep the data secure and only used for the purpose of displaying the experience), and Apple can take a reasonable fee for the privacy and availability of such a service that it hosts, adding another service-based revenue stream. It's a good way to capitalize on its user base without "selling" its customer information... Instead, they're just getting paid to be a watchdog over your private device metrics to let you experience more types of media online worry-free.
 

fredrik9

macrumors 6502
Sep 30, 2018
357
444
Sweden
Not sure how much this would preserve privacy, but at the same time I can't imagine accelerometer data is very largely used in mobile web dev in the first place.

Sounds more just like security theatre being put on by Apple, but if anyone out there knows something I don't, by all means feel free to enlighten me.

According to the WIRED report: ”the information could fuel various types of attacks, like using ambient light data to make inferences about a user's browsing, or using motion sensor data as a sort of keylogger to deduce things like PIN numbers”

So this seems like it could be a potential threat to privacy and the security of your personal information. Albeit a very small one.
 

brinary001

Suspended
Sep 4, 2012
991
1,134
Midwest, USA
According to the WIRED report: ”the information could fuel various types of attacks, like using ambient light data to make inferences about a user's browsing, or using motion sensor data as a sort of keylogger to deduce things like PIN numbers”

So this seems like it could be a potential threat to privacy and the security of your personal information. Albeit a very small one.
Huh. I never would've guessed! But I mean I doubt Apple would go to this effort if it weren't important
¯\_(ツ)/¯
 

velocityg4

macrumors 604
Dec 19, 2004
7,330
4,721
Georgia
Glad this is something that is off by default. Since most people wouldn't even be aware of it and leave it on. Not due to preference. Just because they don't know any better.

I know it sounds like nothing. Accessing motion and orientation data. If someone can use it. Someone will figure out a way to abuse it.
 

citysnaps

macrumors G5
Oct 10, 2011
12,341
26,624
Not sure how much this would preserve privacy, but at the same time I can't imagine accelerometer data is very largely used in mobile web dev in the first place.

Sounds more just like security theatre being put on by Apple, but if anyone out there knows something I don't, by all means feel free to enlighten me.

I think there's some potential for collected accelerometer/gyroscope data to be exploited with respect to creating motion/location profiles of a phone user. It depends on the accuracy and drift of the sensors, time references, signal processing techniques employed, required accuracy, etc.

I wouldn't be shocked if a very clever individual/company could create something interesting of value (ie, sellable processed user information) from collected raw sensor data.

I'm glad Apple is thinking ahead with respect to the possibilities and privacy implications.
 
Last edited:

VictoryHighway

macrumors regular
Jun 22, 2008
155
151
Hopedale, MA
Interesting. The limitations to interactive ad or experiential campaigns would be frustrating for many companies that have things in the works. But this would provide another potential opportunity for Apple, which they really should look into: an internally-hosted and -approved ad platform. Apple should offer a way to have interactive ads that rely on iOS device information to the company for review and eventual hosting once approved. This way, they keep control of where that data goes (I think many trust Apple more than any other company to keep the data secure and only used for the purpose of displaying the experience), and Apple can take a reasonable fee for the privacy and availability of such a service that it hosts, adding another service-based revenue stream. It's a good way to capitalize on its user base without "selling" its customer information... Instead, they're just getting paid to be a watchdog over your private device metrics to let you experience more types of media online worry-free.

They had that. It was called iAd and it was a major flop.
 

vicviper789

macrumors 6502
Jun 5, 2013
376
2,026
Not sure how much this would preserve privacy, but at the same time I can't imagine accelerometer data is very largely used in mobile web dev in the first place.

Sounds more just like security theatre being put on by Apple, but if anyone out there knows something I don't, by all means feel free to enlighten me.


It’s legitimate, there are algorithms to figure out your keystrokes based on gyro and accelerometer data. MIT demo’d it a few years ago IIRC.

Update: done is 2011

https://arstechnica.com/gadgets/201...log-your-pc-using-your-iphones-accelerometer/
 

lunarworks

macrumors 68000
Jun 17, 2003
1,972
5,213
Toronto, Canada
According to the WIRED report: ”the information could fuel various types of attacks, like using ambient light data to make inferences about a user's browsing, or using motion sensor data as a sort of keylogger to deduce things like PIN numbers”

So this seems like it could be a potential threat to privacy and the security of your personal information. Albeit a very small one.
There's unethical and sneaky platform developers working tirelessly on anything that can collect data on you. They're basically ruining everything for everyone.
 
  • Like
Reactions: BulkSlash

ArtOfWarfare

macrumors G3
Nov 26, 2007
9,596
6,112
Wait - you can access ambient light data on a website? I was doing some ludicrously complicated calculations from GPS data to determine if the sun was up or not at your location to determine whether to be in "day mode" or "night mode"...
 

Mr. Donahue

macrumors 6502a
Sep 17, 2014
505
696
I wish apples own apps would turn when you need them to. It’s like the gyroscope since iPhone 6 has been horrible.
 

lovehateapple

macrumors 6502a
Oct 15, 2015
639
970
USA
Not sure how much this would preserve privacy, but at the same time I can't imagine accelerometer data is very largely used in mobile web dev in the first place.

Sounds more just like security theatre being put on by Apple, but if anyone out there knows something I don't, by all means feel free to enlighten me.


While I'm inclined to agree with you, the recent revelations of how facebook was circumventing apple's privacy policies with its "research" app, makes me thankful apple has made this an opt in feature rather than opt out. There's no telling how google or facebook could exploit the accelerometer and gyroscope to parse user data for their own nefarious purposes. It's been proven that all these companies need is a toehold into people's devices and they will find a way to extract whatever info they can from them. That being said, if turning the accelerometer and gyroscope on allows me to access a better experience on some websites it might be a trade-off I'm willing to make. I like the idea of having user prompts each time I visit a website that wants to access motion data from my phone.
 
  • Like
Reactions: brinary001

citysnaps

macrumors G5
Oct 10, 2011
12,341
26,624
Is knowing which direction my phone is facing really an invasion of my privacy?

What if thousands of those points were collected along with acceleration data over time, as you are driving/walking around somewhere, perhaps referenced from some known location?

Implied in the above are some technical assumptions about the sensors (such as accuracy and drift, etc), but you get the idea.
 
Last edited:
  • Like
Reactions: simonmet

manu chao

macrumors 604
Jul 30, 2003
7,224
3,031
This article seems to be misleading. It doesn't seem to me that Apple is limiting access; it seems to just be making that feature "opt in" rather than "opt out".
Which has the de facto effect of limiting access significantly. "Limiting access" does not mean "cutting off access completely".
[doublepost=1549302173][/doublepost]
I like the idea of having user prompts each time I visit a website that wants to access motion data from my phone.
Fully agree, this could work like today's way for websites to access location data.
 

simonmet

Cancelled
Sep 9, 2012
2,666
3,664
Sydney
Notified in 2017, actioned in 2019! C’mon Apple, if you want to claim a focus and priority on privacy you have to do better than this!

It was revealed recently that Apple waited over a week until the eavesdropping flaw became public knowledge before disabling group FaceTime ... a few days later! Sorry, but a privacy-first approach would’ve been to cut it off immediately, then work on the fix as quickly as possible.

Apple seems happy to use privacy as a big aspect of their marketing, but they can still be doing a lot better. They probably care more about users perception of privacy, because it’s this perception that affects brand value and customer loyalty.

This article seems to be misleading. It doesn't seem to me that Apple is limiting access; it seems to just be making that feature "opt in" rather than "opt out".

It’s currently not possible to opt-out, so they are offering the ability to limit access, and the article implies you’ll have to grant access in the same way you do for all the other privacy settings. I don’t think it’s misleading.
 
Last edited:

Khedron

Suspended
Sep 27, 2013
2,561
5,755
  • Like
Reactions: simonmet

falainber

macrumors 68040
Mar 16, 2016
3,497
4,107
Wild West
Finally! I was getting really concerned about Google being able to learn the angle I am holding my phone at.
 
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.