If you want to take a moral stance to not do your job, you quit. You can give a long, eloquent speech if you want. You can write an essay about why you quit. You can start a gofundme. But you do not get to refuse to do your job and keep drawing a salary. That is trying to make a moral stance without a cost. It has nothing to do with Apple having better lawyers, and everything to do with the engineer not understanding what a job is, or what a moral stance is. The moral stance part is where you forego the income from doing something you disagree with, not refusing to do it and getting to keep the income.
In this case Apple's legal department had identified the serials and IMEIs as PII.
This is why the case is in civil court and not criminal (because Apple didn't violate any "laws" as you claim). It is a contract dispute.
according to the article, he alleges Apple was doing something "without required customer releases"; there's at least the implication that a regulation is being broken, do you know something extra about this?
> Boardman believed the meeting would finally address both issues.
> Apple fired him the next day.
This is a reminder that being honest with a company doesn't benefit you.
I'm not sure how changing your IMEI would get you blacklisted any more then if you switched your SIM between phones.
IMEI is not GAID (Google Ad ID) or IDFA (Identifier for Advertisers, for iOS devices), which can be changed. Google Android allows users to change GAID (in a rather cumbersome process), some privacy-conscious Android alternatives automate this on a regular basis AFAIU.
IMEI doesn't function like a MAC address, which can also be changed with relatively little concern (though it's helpful to present the same MAC to the same network on repeated connects, particularly if that network limits access to known MAC addresses, a ... rather weak form of security).
Moreover, IMEIs are useful in limiting the usefulness of stolen devices, as the IMEI can be added to a blocklist by carriers to prevent their use on networks. There's been (unsuccessful to date) legislation proposed in the US to ban IMEI modification entirely. In practice it is possible to change IMEIs, but that would effectively result in the device being unrecognised by the carrier, and new service under the new IMEI would have to be established. This isn't something you could do easily while continuing to use the same number (absent, say, number portability ... which would defeat much of the identity skirting), though it might fit some use cases.
IMEI is largely present only on phones with SIM or eSIM capabilities, but is independent of the SIM itself. Changing the SIM/eSIM will NOT change the IMEI.
<https://en.wikipedia.org/wiki/International_Mobile_Equipment...>
More generally: it is hard to make cellular device use private, given that effective identity leaks occur through so many channels. Location, proximity to other devices, patterns of use, patterns of contacts, billing information, associated phone numbers, other account contacts, and the like. Much as I'd prefer otherwise, a given phone probably maps pretty closely with an individual or small group (family, household, business location / work crew, etc.). That's pretty intrinsic to how the system functions.
Securing data on the device may be more tractable, but limits exist there too.
As for recovering stolen phones, nobody does this. Also, it is possible that criminals know the ways to modify it anyway. As I am aware, there are proprietary software for unlocking Android phones locked with theft prevention. This software can be rent on a pay-per-hour basis. Maybe they have software for IMEI editing as well. And even if changing IMEI is not possible, the criminals will rather sell the stolen phone for parts, than return to the owner.
In Russia there are plans to create an "IMEI database", so that when you buy a SIM card, you must specify the IMEI of the phone it will be used in.
> Much as I'd prefer otherwise, a given phone probably maps pretty closely with an individual or small group (family, household, business location / work crew, etc.).
If you buy a SIM card without a passport, pay with cash and use it for Internet access, it is mostly anonymous.
This may change, obviously. Likely for the worse.
First is strong and enforceable law that makes it unlawful to violate one's privacy. The second is to prosecute violators directly—that is, employees cannot hide behind corporate walls and allow the corporate entity to take the blame.
Irrespective of what employers demand, employees have a responsibility to obey the law. Risk of individual employees being chucked in the slammer would change corporate culture overnight.
Fining corporations alone is a waste of time, they see such fines as the cost of doing business, losing one's freedom for an individual is another matter altogether. Employees must be frightened of the consequences of violating the law or the practice will continue.
This is not an indictment - it is merely an observation. (to mimic gpt-style for a moment)
Shame on you, Apple. If you want to keep your reputation, be better.