June 28, 2007 | By Peter Eckersley

Privatunes 0.9 does not anonymize iTunes Plus files

Slashdot and Wired Compiler ran posts yesterday about Privatunes, a program that claims to remove personally identifying information from iTunes Plus files (the current version is closed source and Windows only, thought the site says that this will change in the future).

Privatunes 0.9 overwrites the user's name and address. Unfortunately, the Privatunes coders didn't read our last post about iTunes tracking data — aside from the name and email address, there are other fields that Apple, or a litigant that subpoenas Apple, could use to identify the purchasers of iTunes Plus files, even if they've been run through Privatunes 0.9.

There are two fairly large fields, marked sign and chtb, that are unique to each copy of a given track. There are also several other places where copies of the same song vary by three or four bytes (they can be readily observed with a program like vbindiff). It should be assumed that a file is potentially identifying unless all of these fields have been overwritten.

Lastly, Privatunes 0.9 just overwrites the name and email address using ASCII spaces (0x20). This means that the length of these two fields can still be seen after the file has been modified. For complete anonymization, these lengths should be made unreadable.


Deeplinks Topics

Stay in Touch

NSA Spying

EFF is leading the fight against the NSA's illegal mass surveillance program. Learn more about what the program is, how it works, and what you can do.

Follow EFF

Here’s how Computerworld covered EFF’s birth 25 years ago https://eff.org/r.a34f

Jun 30 @ 1:28pm

Copyright should not be used to turn students into criminals for sharing a research paper online. https://eff.org/r.uy7p #standwithdiego

Jun 30 @ 12:38pm

Are you an amazing writer looking to defend the future of civil liberties? We have the perfect job for you: https://eff.org/r.2773

Jun 30 @ 10:43am
JavaScript license information