iOS 11 Location Privacy: "Only While Using" is now always an option for users
twitter.com
twitter.com
Hopefully sometime soon Apple will also encrypt iCloud contents so data from non-american people (europe in my case) is protected against the US government prying eyes.
Our data/privacy seems pretty well protected inside Europe, but in America we seem to have 0 privacy rights (America first...!)
As far as I've read, the iCloud backups have always been encrypted at rest, and Apple is apparently working on improving it to the point where they do not hold any decryption keys to the backups [0].
That's why, when you set up a new device, up until now it would not have your message history - because the message history can only be decrypted on devices that are already-authorized. If you restore a backup in its entirety, that includes the message log and the encryption key, but if you set up the device as "new", you only get the newly received messages - since it needs your password to decrypt the backup, it had no way to decrypt the message history from backup on the cloud and only sync that down to the new device (which always bothered me in terms of convenience). I think they're working on improving the usability of it in upcoming releases though.
[0] https://9to5mac.com/2016/02/25/apple-working-on-stronger-icl...
I also recall from the San Bernadino case that the FBI/Apple had the ability to get historic message history from the iCloud backup but the FBI pushed for decrypting the device because of the most recent and not backed up messages.
As for your scenario -- doesn't that explicitly confirm that the messages are not encrypted safely at rest? You can restore to an entirely new device, using the same backup, and retrieve the messages.
Right, but do they retrieve them from iCloud? Without Apple's assistance, and without knowing the user's password?
> I was pretty skeptical but I've yet found any proof or documentation from Apple's support docs disproving this.
Well, here's the brief overview: https://support.apple.com/en-us/HT202303
and here's the iOS security whitepaper: https://www.apple.com/business/docs/iOS_Security_Guide.pdf
Which includes a section about iCloud security, including the following section:
iCloud secures the content by encrypting it when sent
over the Internet, storing it in an encrypted format,
and using secure tokens for authentication.
I am no security expert, but I am pretty sure FBI wouldn't have a huge fight with Apple if they had any way to get to the data directly (and once they figured out they could use a vuln in the old iOS to break into the device, they did indeed drop the fight).> FBI/Apple had the ability to get historic message history from the iCloud backup
Right, because they reset the shooter's Apple ID password. Not because the backup was in plaintext.
> As for your scenario -- doesn't that explicitly confirm that the messages are not encrypted safely at rest? You can restore to an entirely new device, using the same backup, and retrieve the messages.
How does that follow? You still need to supply your password to decrypt the backup before you can restore it. From the same security whitepaper:
When files are created in Data Protection classes that aren’t accessible
when the device is locked, their per-file keys are encrypted using the
class keys from the iCloud Backup keybag. Files are backed up to iCloud
in their original, encrypted state. Files in Data Protection class
No Protection are encrypted during transport.
The iCloud Backup keybag contains asymmetric (Curve25519) keys for each
Data Protection class, which are used to encrypt the per-file keys. For
more information about the contents of the backup keybag and the iCloud
Backup keybag, see “Keychain Data Protection” in the Encryption and Data
Protection section.
The backup set is stored in the user’s iCloud account and consists of a
copy of the user’s files, and the iCloud Backup keybag. The iCloud Backup
keybag is protected by a random key, which is also stored with the backup
set. (The user’s iCloud password isn’t utilized for encryption so that
changing the iCloud password won’t invalidate existing backups.)
While the user’s Keychain database is backed up to iCloud, it remains
protected by a UID-tangled key. This allows the Keychain to be restored
only to the same device from which it originated, and it means no one
else, including Apple, can read the user’s Keychain items.
On restore, the backed-up files, iCloud Backup keybag, and the key for
the keybag are retrieved from the user’s iCloud account. The iCloud Backup
keybag is decrypted using its key, then the per-file keys in the keybag
are used to decrypt the files in the backup set, which are written as new
files to the file system, thus re-encrypting them as per their
Data Protection class."...and never provides encryption keys to any third parties".
The data might be stored encrypted, but Apple seems to have access to the encryption keys. I've read that they need to be able to decrypt data to be able to comply with government requests.
I'm not sure if this is still the case now in 2017, but i assume so, until i read otherwise :)
https://www.macrumors.com/2016/03/16/apple-to-double-down-ic...
Of course, no one claimed that iCould data was E2E. They also need to decrypt the data in order to serve it to their users.
That's the point, they don't (and shouldn't) need to. As Apple itself says in the above linked article:
"Apple is working to further harden iCloud security so that even it won't be able to access user information stored on its data servers"
1) the company has the encryption key
2) you give the company the encryption key each time you log in and they store it temporarily
3) everything is getting decrypted in the browser locally (probably tremendously infeasible)
Also not American myself, but I think legally it should be quite the opposite: NSA and CIA can "legally" spy non-US citizens. It is illegal for them to spy US citizens.
But in any event, there is only one country with a significant globally active IT industry and a capable globally active spy agency. That combination is becoming more problematic, which is unsurprising as well.
I've been saying this for awhile, that I trust Apple a lot more since they aren't directly incentivized to sell out their users for advertising. I LOVE iOS as a platform, as a user of both Android and Windows Phone there is simply no comparison, iOS blows both away.
Is that due to Apple being pro consumer privacy or because they have $250 billion in cash? When the cache of cash drops does Apple start adding ads and tracking its users?
It is nice that Tim Cook is pro consumer privacy and that gets baked into the company culture, but Apple is also financially motivated to continue this stance (it's a major differentiating factor and marketing point).
My Android phone worked out my home and work location without me telling it. That was a bit weird.
My colleague was really impressed by Google Photo's automatic indexing of pictures being able to find the most obscure objects in pictures
Location privacy controls and more have been in Windows since Windows Phone 7 and Windows 8.
https://privacy.microsoft.com/en-us/windows-10-location-and-...
https://www.tenforums.com/tutorials/13225-turn-off-location-...
Maps and Pandora, no, browser and email, yes.
(this is admittedly a pain, and Apple enforcing in-use-only option availability is a welcome change)
My Chinese girlfriend disputes this. Even the iPhone SE is a bit big for her, and it's just there to consume left-over parts rather than to be a living branch of their design space. No touch-screen phone maker is really serving the Asian market at this point, as far as "idiomatic" one-handed usage goes; they're seemingly expecting everyone with small hands to just treat their phones like phablets, juggling them around in both hands every time they want to tap anything.
Unfortunately Google doesn't care about your privacy. In fact, it's only a matter of time before they remove coarse locations and/or give every app full access to location data (the same way they did with internet access).
There's currently no explicit penalty for requesting too much information, but the battery power indication could probably get users to uninstall apps wasting energy, and it can even get you app terminated.
[1] https://developer.apple.com/documentation/corelocation/clloc...
If an app never needs more precise information than the country (say Spotify trying to decide whether they operate in your country), they don't need to request it. That also guards against bugs or security breaches in apps that try to do the right thing.
I also very much like being able to use the geolocation in my photos to find ones from an exact location.
Plus my memory of my personal life is so unreliable, especially if I don't have any context, so if I'm ever in court I'd like to be able to share exactly where I was when I was there.
I've stopped thinking that real privacy is attainable. That being said, I refuse to share it with scummy companies like Uber.
Moves is owned by Facebook (one has to decide for themselves about FB's scummyness).
RE people saying "just take a photo and use EXIF", that won't work because I don't know in advance what locations I will be interested in in the future.
(I edited the comment to use "in advance" instead of "ex ante" though.)
https://itunes.apple.com/us/app/where-have-i-been/id64155398...
Google's location history is excellent and I'd gladly pay for an equivalent application which I could self-host and set up with the minimum of hassle, but having them do it creeps me out too much. I've not managed to work out how to get OwnTracks to substitute fully for it.
I also wish the NSA had something like a personal data explore, but I know that will never happen.
A car dealership who botched a warranty repair on my vehicle is stonewalling me - once they realized the error was likely to cost them $2k - $3k, their service department deleted my file and began claiming no evidence exists that I had ever been to their location. I got the scheduling department to confirm my appointment and just found my location history for that day showing that I was at the dealership right on time during the appointment. Going to send this to the manufacturer's corporate complaints departments. Thanks for the heads up.
It's great to have control, and it would be even better if we were able to specify the accuracy an app is able to achieve. But there are obviously some reasonable use-cases for both foreground and background tracking.
Agree with the OP that Uber can burn in hell for "always on"; I guess just in case I need an emergency Uber ride :-/
But feel free to just uninstall all those other apps that I love using.
For example, if I need my app to be woken up remotely by a Bluetooth peripheral that requires the "always" location permission to function.
I dislike this feature intensely, so I actually have my location services turned off, and I only turn it on before using Waze or Maps.
(Oh, and it seems that the Apple "Use location to set timezone and GPS to set time" will use the GPS even if you turned that specific feature off - unless all location servies have been turned off. Or at least, that's my experience, but it might just mean my phone is bugged).
You sure it isn't just getting that info from the cell towers?
When the entire "location service" is off, it does not happen (it might use the services for all I know, but the indicator doesn't light up)
https://www.imore.com/how-only-allow-apps-see-your-location-...
> Keep in mind that some apps may not show all three options. This is most likely because the developer has not yet implemented the while using this app option.
If they chose "while in use" then a ton of functionality would never be possible for any user whatsoever... because the only options they had were, to coin some temporary terms:
Option A: "All or nothing with behavior 1 (while app is in use only)"
or
Option B: "All or nothing with behavior 2 (always use location whether app is in use or not)"
If they chose option A, their app would be a lot less useful.
If they chose option B, they piss off some people who think they should have offered option A. But Apple would not allow them to offer both option A and option B.
Now, with this upcoming change in iOS 11, Apple will allow them to offer both options, if they choose to.
So I wouldn't hold my breath.
Related screenshots:
* Uber requesting location access: https://twitter.com/joeduvall4/status/872007928844345344
* Apps using background location now displayed more prominently: https://twitter.com/ow/status/872145515386982400
If it isn’t, Apple should give an option to turn the banner off.
http://www.jpost.com/Business/Business-News/Google-announces...
Wrong, and it's especially irksome that just because you cannot think of a good reason, you leap to the unfounded conclusion that there is no good reason.
When you are driving and not using the app and not even thinking about the fact that you have the app, and not planning to use it, it can still be gathering useful traffic information to help route other users according to the current conditions on the route you are traveling. By the way this takes a super negligible amount of power because it can piggyback its use of system services (location, data transmission, etc.) on top of other already running services.
There is no opting everyone in by default for location on iOS. They have to explicitly opt themselves in, if they want to. Otherwise they are opted out by default. This goes for all apps and is enforced by Apple in order to maintain a good experience for the user.
Some examples:
It's useful to know when you have arrived home and are no longer moving.
It's useful to know when you have started moving and left home.
It's useful to know where your home is so that it can guide you home and for other traffic related reporting reasons listed above and below.
It's useful to know where other homes are or other places you spend time, where it may be significant that you are arriving and staying for a long time, as opposed to for just a minute or two (as at a traffic light).
It's useful to know that your non-motion is not an indication of traffic being stopped on your road.
It's useful to know that non-motion when you are away from your home may be an indication that traffic is stopped on the road you are on.
All of these are directly relevant to explicit, openly featured Waze use cases.
I see way more locations and rides than I actually navigated to with Maps. For most of the time, it is just installed.
I now manually disable all location services.
I'm not saying it shouldn't be opt in rather than opt out, it should, but that's still a far way away from hiding it from the user.
PS: I'm a very big user of permanent location history and it's a feature I enjoy, I would actually like to make it more granular / precise with more regular updating of my position if possible.
http://www.iphonehacks.com/2016/10/how-to-turn-off-hidden-fe...
All that will go away, but on the other hand I really don't expect them to support 32bit apps forever. You always have the option of simply not upgrading iOS. It's a trade off.
Unfortunately, Apple gives you no way to opt-out of updates. I've figured out a way to block them at the firewall level, which seems to work, for now.
Constant popups _are_ the means to force updates. In addition they also throw up a nagware screen where they trick you to enter your pin to schedule updates. Apple employs several dark patterns, on iOS, and also on MacOS to trick the user and its rather sad to see them follow MS/FB/Google.
>I believe you'll get prompted again every time a new update is released,
That is not true. They do it multiple times for the same update. Look, I wouldn't care if they were simply security updates, but Apple updates bloat up and slow down the phone over time. On top of that, what makes it even more egregious is that they make it impossible for me to downgrade, and go back to a state where the phone was working just fine and I was happy with it.
>but hitting "Ignore" occasionally is a small price to pay.
You make it sound like its once in a year. Unfortunately, Apple constantly nags you to the point where, unless you're constantly looking out for it, its easy to accidentally hit the wrong button. Its sad that they have had to resort to tricking the user to drive their update stats.
Bullshit.
They show an alert saying something like "A new version of the OS is available." [Update] [Ignore].
That's not a dark pattern. It's easy to just Ignore. I have a number of development devices using older versions of the OS and I've never had any problem avoiding updates.
> On top of that, what makes it even more egregious is that they make it impossible for me to downgrade
That's mostly the fault of the baseband.
> Apple constantly nags you to the point where, unless you're constantly looking out for it, its easy to accidentally hit the wrong button.
This is just flat-out wrong.
> Its sad that they have had to resort to tricking the user to drive their update stats.
And this is actually fairly offensive.
that was the last android phone I owned.
The differences between feature sets on different generations is less and less it seems though. If I recall correctly, the differences between the iPhone 3G and iPhone 4 was bigger than for instance iPhone 6 and iPhone 7. If I weren't such a sucker for new and shiny things, I'd probably buy an iPhone SE today.
That said, they force developers to discontinue support for old iOS versions, so if you don't upgrade, you'll stuck with old apps and some might stop work if they rely on remote servers with changed protocols. So if you want to use iPhones, be prepared to buy new phone every 3-4 years.
But if your device is a few years old… You're right that you may want to wait and see what the reviews say. Sometimes the updates actually make the phone feel faster, but sometimes (like iOS 7 with all the new transparency effects) it definitely can be a worse experience.
You can target at least back to iOS 7 (https://forums.developer.apple.com/thread/50410) that gives you support for phones back to the 2010 iPhone 4.
Apple also will allow you to download an older version of an app if the newest version doesn't support your hardware. I can confirm that this works back to devices that only support iOS 5 - like my first generation iPad from 2010.
Killing 32b-only-applications i do not like :/
As for speedup/memory gain, merely launching a 32-bit app will cause the OS to get a bit slower / use more memory until such time as the app is actually killed by the system. Merely going back to the home screen isn't good enough, since apps stay suspended in the background until the OS decides it needs that memory back. And if you have any 32-bit apps that actually do background processing, you'll end up with 32-bit apps in the background frequently.
Less than half as 32b code objects will be smaller than 64b ones, but even if it's half how much storage is that exactly? I mean I probably have games bigger than the frameworks on my device.
> As for speedup/memory gain, merely launching a 32-bit app will cause the OS to get a bit slower / use more memory until such time as the app is actually killed by the system.
Well yeah so it's just pay for what you use aka who gives a shit.
> And if you have any 32-bit apps that actually do background processing
Which is unlikely given the vast majority of applications being killed by this move are games.
I mean let's be honest for once, the gain from removing 32b frameworks is pretty much entirely on Apple's side, there's little gain to be found for end users when they're not just plain losing value in this move.
I've given you multiple concrete benefits to end users. You may not personally care about the code size difference, and you seem to be completely discounting the speed / memory usage issues, but just because you personally don't think those are a big deal doesn't mean they don't actually exist.
There are not benefits since they break software. You can get pretty much all of these by just removing remaining 32b software from your system.
1) Just removing all 32-bit apps doesn't recover the disk space used by the 32-bit versions of frameworks, and
2) If you remove all 32-bit apps, then there's literally no point to retaining the 32-bit OS support anyway.