Apple does right by users and advertisers are displeased
eff.org
eff.org
I think it's a genius move. People will begin to understand in the coming years just how much information these companies are tracking/extracting, and turn(or stay) to Apple.
I think users would care about privacy, if they truly knew just how much information is being gathered.
Care about privacy? Ok, don’t use gmail instead setup your own mail server and configure gpg.
Vs
Care about privacy? Ok: use apple products when they work for you.
And with regard to displeasing shareholders - Tim Cook has no problem with that - to quote, "if you want me to do things only for ROI reasons, you should get out of this stock."
http://www.businessinsider.com/tim-cook-versus-a-conservativ...
Tim Cook is no Steve Job, but Steve Jobs was no Tim Cook. They’re good at different thing, but Tim Cook will probably go down in history as one of the greatest CEOs of all time.
They see the Mac like a truck. Yes, most people will buy cars, but we'll always need trucks too.
Further, best as I can tell, Mac continues to grow, both fraction of new sales and installed base.
(Besides Apple's CEOs tend to last a long time. 14 years with Jobs at the helm for example, and 6+ years with Cook and counting).
I think a mismatched CEO would either lose fighting it, or destroy the core of what makes Apple great, which shareholders will not like.
https://www.macobserver.com/tmo/article/tim-cook-soundly-rej...
For the record I'm not saying they are taking this stance for some charitable reason, I'm saying it would/could make financial sense for them, especially considering their branding as a premium product.
Taking it one level of abstraction up, I don't see a future where using your data for efficient targeting of advertising isn't happening (and I don't consider that an obviously bad thing), and I consider Google a net positive force in shaping a responsible way of doing that.
Apple is underdog in services. To this day Apple Maps is a pale shadow of Google Maps. They're getting better to be sure, but still an underdog.
Apple maps transit experience is, in my opinion, much more carefully though out than Google's, so I know they can do something with the right information.
It would be nice if Apple users had the ability to submit corrections to Apple somehow.
What's neat about this is if you report a map error and they correct it, you actually get a push notification telling you that it's been fixed.
Isn't basically all your data, everything you type being sent to Apple?
No. And I have looked.
Apple is very up front about the features that do and don't talk to the mothership. It has been a while, but I recall that as you go through the setup process, there's always info available telling you when they'll see your info, and more info online. But it tends to be pretty obvious - Apple has slurped up sensitive data before[1], but it did look like an accident, they fixed it, and were forthcoming about what happened.
They're very clear that security related stuff (Secure Enclave - the thumbprint/faceprint data) never leaves the device.
Things I know that talk back:
- App store (obviously, and they care about analytics) - News app (ditto, it is basically a thin web browser) - iCloud (ditto, clearly, and pay attention to the various modes for encryption: IIRC, you need 2FA enabled for the encryption key to not be recoverable on their end. But you should double check for yourself, I don't use iCloud, so I haven't paid attention.)
And looking at my phone on my local net with Wireshark, I also see some chatter that looks like things saving config information, similar to what you see on a Mac. I'm guessing this is them just not being careful - they want everyone backing up to iCloud, and even though I don't, various daemons keep nattering. I block all that stuff when on wifi (both Mac and iOS), with zero problems.
On iOS, you mainly need to be concerned with third-party apps. Some of them build in shady libraries for adtech shitheads, do stupid things with analytic/instrumentation libs, etc. The ecosystem seems less bad than Android, at least.
As close to a bottom line as I can come: turn off cloud backup and the syncing crap, use 2FA, don't download sketchy free games that ship your data to some guy in Romania, and you're leaking significantly less than on Android. Take more precautions (a content filter/ad blocker more aggressive than the defaults, disable wifi and bluetooth to avoid snoops along wherever you go, run your own mail/calendaring, etc.) and you're in pretty good shape, relatively speaking, and depending on your threat model.
[1] IIRC, location data was being logged such that it ended up being sent back in crash reports.
Issues with iOS include:
* iCloud not encrypting data securely serverside (i.e. they can potentially get at the data). You can avoid this by not using iCloud. * They have Ads in app, and now in the Appstore directly. Potentially this changes the dynamic, between user/advertiser in a negative way.
There are probably other issues... but I'm not currently aware of them. Overall it still seems like the best option from a privacy perspective.
When I didn't used 2-step, I forgot my password, called them and they reset it for me (I had to confirm my identity providing them a code sent to my mac).
"All iCloud content data stored by Apple is encrypted at the location of the server. When third-party vendors are used to store data, Apple never gives them the keys. Apple retains the encryption keys in its U.S. data centers."
and
"iCloud content may include email, stored photos, documents, contacts, calendars, bookmarks, Safari browsing history and iOS device backups. iOS device backups may include photos and videos in the Camera Roll, device settings, app data, iMessage, SMS, and MMS messages and voicemail. All iCloud content data stored by Apple is encrypted at the location of the server. When third-party vendors are used to store data, Apple never gives them the keys. Apple retains the encryption keys in its U.S. data centres. iCloud content, as it exists in the subscriber’s account, may be provided in response to a search warrant issued upon a showing of probable cause."
So in short, Apple retains encryption keys for much of the data (including iOS backups), and will provide decrypted data to US law enforcement on request.
https://www.apple.com/legal/privacy/law-enforcement-guidelin...
Much of the data listed as encrypted on server is available to US law enforcement under warrant.
It would be nice, to have an option available where data is encrypted on server, with your key. But that would mean you couldn't recover your data if you lost your key of course (and I think Apple consider that a poor user experience, or are under pressure not to do that...).
https://www.macrumors.com/2014/10/20/apple-spotlight-suggest...
see also
http://bgr.com/2015/04/01/iphone-location-tracking-map/
I recommend don't trust Apple. It's not your code, it's not your hardware.
So turn off Spotlight Suggestions? Obviously if you're searching the web there will be traffic to the search engines.
> http://bgr.com/2015/04/01/iphone-location-tracking-map/
Frequent Locations is on-device only.
It may be on-device only but it's not clear to the end-user that it's happening at all. No visible setting to disable it and vulnerable to malware.
Yeah, it is. Welcome to what it feels like to be wholly the customer, instead of partially the product.
As Richard Stallman said, Apple puts the user in a prison. Just because the warden is getting better at playing nice some of the time and making the prison more beautiful doesn't change the fact it is a prison.
In a free system, the users could have done this themselves years ago instead of waiting for Apple.
With that said, the FSF endorses Replicant (which actually just had a new release and added more device support[0]). I use Replicant.
Given the free software philosophy, a free program is always superior to a non-free program, no matter how bad that free program is. But Replicant isn't bad; the most recent version is a fork of "the latest changes from LineageOS 13.0 ".[0]
What this emphasizes is the need for a fully free/libre mobile device, which has been the topic of other HN discussions.
[0]: https://blog.replicant.us/2017/09/a-new-replicant-6-0-releas...
I never understood this opinion. If I need to navigate to drive to my grandmother's house, and none of the free nav software knows how to get there, but I have access to some proprietary software that will do the job, then why not use it?
I can stop using it at any time I want, no strings attached. I can also reason about its ability to perform actions that serve its creator's interests rather than mine (capture my data and send it to the mothership, mine bitcoins on their behalf, ...) and I can make rational decisions about whether the ability to find my way to grandma's house is worth the risk. Often, the math works out that I am better off occasionally using the proprietary software.
So if the rooted tweaks and apps market isn't that strong for Android, how big would the side loading market be? I'm obviously thinking there's not much there. At least not for people where Google services and apps are included normally with Android like the US.
I'm not aware of any android phone where you can't install whatever apk you like.
So no, your comparison of iOS to Android does not apply 1:1.
I don't care if you call it a "grandstand PR move". It detracts from what Apple has actually done. It was not a valueless statement of ideals. It's an actual piece of functionality that millions of people will have built into their smartphones.
Stallman sits around hypothesising about vague 'open systems' that—when fleshed out—are completely impractical for the average user. This does very little. You can all sit around installing AOSP (or some other lesser-known open-source mobile operating system) and write your own ML-powered cookie bucketing engines and pretend that this is a viable alternative, and that Apple hasn't done something objectively pretty cool and great.
Thee fact is, the Stallman philosophy is absolutely meaningless to the vast majority of end-users, and they are incapable of doing anything with it. What Apple has done is something that will help end users. It's a selling point, they might win some people over with it, boo hoo, there's no such thing as ethical consumption under capitalism. It still means a whole lot.
It is like high art. Lots of people rarely look at modern art, but it doesn't mean it doesn't influence the design and pop-art they do see regularly, indirectly.
You are wrong to present behaving like Stallman and what Apple is doing as things that are competing alternatives, with things being in one camp or the other. Stallman's work influences the mainstream, so mainstream, less extreme, changes and what he does are not unconnected.
You can view a castle as either a prison or a refuge, depending on your political inclinations. Apple has built a very robust castle -- whether that's a good or bad thing depends largely on your personal views. Stallman detests all castles; empirically, most people seem to find them comforting.
Here's an interview with Steve Jobs on privacy regarding location data:
https://youtu.be/39iKLwlUqBo?t=23s
Apple takes care of their users.
With Android, I can choose to load my own OS. With iOS, I cannot.
I would argue that some of the perceived 'hostility' is a Necessary Evil® for improved UX elsewhere - specifically implementing DRM paved the way for Apple users to be able to "just buy/lease/get/download" lots of media (or actually licenses to media) very easily. I'm an Apple FanBoi though, so I am heavily biased because I really like their ecosystem.
Specifically about user privacy, Apple has a track record of being a decent advocate for user privacy. More publicly than I have been, that's for sure!
But the company who does:
http://bgr.com/2015/04/01/iphone-location-tracking-map/
https://www.macrumors.com/2014/10/20/apple-spotlight-suggest...
... no thanks.
That's had a toggle in Settings for several years. Also "Significant Locations are encrypted and cannot be read by Apple."
The problem is also vendor lockin and customer loyalty (often times because people don't like change). You can leave, but most users won't or don't want to.
Jailbreaking is not part of the lock-in. It's a way of doing more stuff with the hardware than the original software allowed you to do. The fact that the term has 'jail' in it doesn't make the users more locked in than they already were, they were free to enter and leave without jailbreaks.
Tangentially, I used to jailbreak my iphone because it offered me useful extra features that I couldn't otherwise get (e.g. a SSH client back when Apple didn't have such apps). But I haven't felt the need to jailbreak iOS for years now, because just about everything I could want to do with the system is already possible.
Finally, 'jailbreaking' is effectively another word for 'security hole'. If my iOS device can be jailbroken, it's actually a worry to me, not a benefit.
Google's chromebooks do offer a better alternative to this, whereby you can flush out ChromeOS by making a physical change to your device (in my case, disassembling the laptop and turning a particular screw). But it still can be a security risk; if there was some physical means of replacing iOS on a phone with alternative software, you could never trust that a secondhand iPhone hadn't been maliciously tweaked to preload malware.
That's precisely what rms is referring to when he says "jail":
https://www.gnu.org/proprietary/malware-apple.html#jails
"allowed you to do" is the key phrase in your sentence---software should never tell you that you can't do something just because its developers don't want you to do so (we call that an "anti-feature"); software should be a tool to serve the user, not hold their computer/device hostage to exert control over them.
If the users "could have done it themselves", we should have proof that someone did it in a way most people could use it. Where's such a system? Which mass market usable mobile OS does not put users in a prison? If the choices are between one that puts the user in a prison but protects the user better vs. another that doesn't, the decision for those who value this and can afford such a device is quite clear.
Uh... Mozilla.
Mozilla, of course, is a great organization on this front. I've said that in comments here in the past, and am an unofficial Firefox evangelist.
Also if a free system lets users do it themselves why are we talking about Apple being a better option for security and privacy over google?
What Apple are you talking about? The one I know has always held customer satisfaction as sacred. They've been fairly developer-hostile, but extremely user-friendly. They're literally famous for being user-friendly.
It can be arguable why Apple limited the user iPhone wise. Actually, limiting the user not only affected performance but also privacy since Apps are jailed and can't easily "hack" your phone/data.
It be great to differentiate between two guys: 1. Who cares about freedom and performance and 2. Who cares about freedom only. I'd like to think that Apple is number 1. They care about freedom as long as it doesn't affect the performance vector.
Could they?
I was dimly aware of third-party cookies and enabled options to block them. Kind of made sense, but only because a big fuss was already being made.
These new tricks for fooling the browser into thinking third party cookies are first party? I wasn't aware of them at all. NB: I'm kind of an HN addict.
Are there any free-software browsers addressing this issue at all? Ones that ship by default with KDE, etc. at least?
Even Custom Android ROMs have inherent design flaws, because it's been ultimately designed by Google and certain things just can't be changed without Google playing along (or breaking compatibility with the app ecosystem).
And rms' perspective: https://stallman.org/apple.html
But it also attacks the revenue of the other 3 horsemen (Google, Facebook, Amazon). Which also pleases me.
If I was Apple, I'd mess with advertising, just because.
Apple focuses on the mass consumer as their sole and perpetual customer. This allows them to maintain laser focus on solving the problems of the end users rather than solving the problems of an advertiser and forcing the solution on end users.
Apple's refusal to "innovate" on its business model has actually put them where they are today. Most other tech companies have other motives in making mobile devices: Amazon wants to sell you content, Facebook and Google want to show you ads, while Apple just wants to make the best damn phone out there and sell it at a very high price.
If the market definition of "best damn phone out there" starts to include "protects your privacy", Apple doesn't have the conflicts of interest that Google or Facebook do. I'm sure everyone else will eventually follow suit, but Apple is the only one with the capability to take the lead on privacy.
What are you talking about? Did iTunes add back DRM? Around 2009 or so Apple made all of iTunes DRM-free and were, I believe, the first major online music store to do so. It was a huge deal; Apple published an open letter from Jobs on their home page and everything.
http://www.nytimes.com/2009/01/07/technology/companies/07app...
"iTunes Plus refers to songs and some music videos* in high-quality AAC format that don't have Digital Rights Management (DRM). All songs now for sale in the iTunes Store are iTunes Plus."
https://support.apple.com/en-us/HT201616
and, as of 2014, you could kill DRM on DRM-ed iTunes purchases made before 2009 https://www.wired.com/2014/03/kill-itunes-drm/
Plus, not all DRM schemes are equal. One that is exclusive to Apple is worse (IMHO) than one that isn't. For example, I can go to a store and buy a DVD or BluRay disk that has DRM yet I am very sure that I can play it on every player I own.
Ultimately if you have the money for a premium phone and just need it to make phone calls, browse the web etc (the basics) then the iPhone really is the best option as it's more secure at the moment.
The place where the iPhone doesn't sell to someone like me is the hand holding babysitting it does preventing you from manipulating the device as I wish. Again this is a non-issue to them.
It can be frustrating to see someone overpaying for what you consider an inferior product but they're not using it like you are.
Really though; there's very little you can't do with an iPhone as long as you're willing to pay $99/yr and write some code...
Personally, I think more than 50% of users would benefit for more flexibility than iOS offers, even at the cost of less ease of use. I don't think it has to cost that much ease of use though. I think the ideal for most people is somewhere in between Android and iOS, but probably closer to Android. Android is not that hard to use. It is also not impossible to have a highly curated app store like Apple's, and allow apps from other sources at the same time of people want to install them. Ideally we'd have more diversity in OS implementations I think, based on one or a small number of actual OSs. Android based OSs that are more heavily modified to be easier to use etc. This would be easier I think if phones were more like PCs in that you could install your own OS and get the drivers for your hardware. I think Android is somewhat moving in that direction so there is hope for that in future.
First, is that phone users value weight and size above all else. Regardless of what that means to each individual user, it does mean that any design compromises will need to come out favorably for weight/size considerations. Modular phones have been released, but they largely failed because they provided very little benefit for the added weight/size. Phones absolutely must be integrated devices as a result (i.e. no modular components, making them impossible to repair).
Second is that because of the above, basically every chip in a phone is a custom SoC. So not only do you have to support many flavors of devices, you also have to support different flavors of SoCs, often used in different ways in different devices. This isn't insurmountable with the right driver repository structure, but good luck getting vendors to update those drivers.
Third, I don't exactly know what benefits a less restrictive OS ecosystem would provide. Apple's App Store rules are not insane (there are so many bad actors out there, the curation is a huge benefit to users); and if you ever want to run programs that aren't "blessed" by Apple, you can buy a $99 developer license, sign the binaries yourself and sideload them through XCode. Could it be easier? Sure, it could. But it's realistically an edge case, and Apple is focused on the main use cases.
> "When you visit a site, any cookies that are set can be used in a third-party context for twenty-four hours. During the first twenty-four hours the third-party cookies can be used to track the user, but afterward can only be used to login and not to track. This means that sites that you visit regularly are not significantly affected. The companies this will hit hardest are ad companies unconnected with any major publisher."
Since the average internet user (aka not us) visits Facebook constantly and Google regularly, will this really have an impact at all?
Google and Facebook may know too much about you, but I'm not really worried about them selling that data, which is some small relief. They are the ferryman at the river, and they charge to take advertisers to their audiences. They aren't in the business of selling boats.
Why aren't you worried about that? How about in 15 years when they've gone downhill and are looking for ways to make some quick cash?
If we don't make headway on this issue legislatively and soon, I'm not sure it matters, as your profile information's privacy at all these sites has a shelf life in my eyes. Both sales and security breaches with exfiltration of data at random adtech companies will eventually lead to most this private profile data being publicly available anyway, so unless we put some strong limits on what can be collected, how it must be stored, notification of who is storing it, and the ability to review and remove items (and all of this at a minimum), I think it's a moot point who has it now, since everyone will eventually.
I know a lot of people have hopes for a legislative solutions, but I think the EU (also UK and others) "cookie law" really needs to make us consider how effective they can be. The motivation for the law was good. They put their finger in the right place. . We got nag screens and little improvment in privacy.
Not every piece of privacy legislation does as little as this, but I still think we need to be wary. Browsers, OTOH, are in a great position to improve user privacy.
Maybe instead of letters to parliamentarians, letters to browser makers?
I recommend watching the film "Democracy"[1], which showed how an EU data protection law went through the process to become law. The "main character" (chair of the process) was a German MEP. The thing I best remember him saying[2] was in response to some lobbyists, who wanted to know why he was pushing back against their business interests when they were all united. The MEP said he primarily represented the thousands of people in his constituency, even though they couldn't afford to send lobbyists to Brussels.
With some stronger wording ("This site shares your data, including the web pages you view and where you click, with the following companies: Google, AdNetwork234, ..., These companies use it to sell advertising to you and may further share your data") the cookie law could have been stronger.
The MEP was in the Green party, but most aren't -- pressure from individuals on other MEPs would encourage other, more business-friendly MEPs, to push back against the lobbyists.
[1] https://www.theguardian.com/technology/2015/nov/14/democracy...
[2] I think it was in the film, but I also went to a screening with him giving a talk afterwards.
The only thing legislation like that does is make companies pay people like me a little more to implement popups that annoy their users.
If, instead, it said "Every click you make on this site is recorded and sent to four unrelated companies" the public might just have taken a bit more notice.
There are signs all over California telling you that the appliance you are going to buy might kill you and nobody cares. You think they are going to care that some unrelated company will find out what you are reading on Medium?
However, these banners have also clearly caused millions of people to ask the question "What's a cookie" which leads some of them to start caring about this issue.
We definitely got the nag screens¹, but improvement?
[1] Which is totally inferior solution technically & ux-wise, because the user/client voluntarily accepts the cookie from the server, and there's already setting for that in the browser.
But everyone construed that cookies <=> nag, because nobody RTFM.
The legislation called for informed consent. Two core issues were left open to definition, in practice. [1] What requires informed consent? [2] What counts as informed consent.
For question 2, a standard answer (nag screen) emerged.
Question 1 is trickier. The cheapest & easiest solution is to just nag, so that’s the default. If you want to drop the nag screen you can deal with question 1, but most don’t bother. Either they want the tracking, they want the easiest option or they want legal CYA.
I think the legislative intentions were good, but this was a hard area to legislate. It didn’t work, IMO.
There's only so much a browser can do against someone who can follow your IP address around. What we really need is ISPs who randomize what the server sees from their pool of IPs and NAT it internally.
It's ISPs that worry me the most. They see all the places you connect to. Even if you use https, they still know the endpoints.
We could have skipped the nag screens with DNT.
Glad to see a large company with leverage fight back.
The ethical concerns are staggering, and as it becomes harder to extract value it seems the ethics violations continue unbounded. People seem willing to do whatever it takes to keep their businesses (and most crucially, the jobs they cannot afford to lose) afloat. I suspect wage slavery is to blame for a lot of this.
It's anecdata, but not a single one of the people I know in media/advertising actually WANTS to be there, and all of them have serious concerns about the business practices. The #1 thing keeping them there in every case is "I need the money".
For those who have the luxury of choice I implore you: vote with your feet, switch jobs, and encourage others to do the same! I refuse to join a company unless I know its profits are tied directly to some mutual benefit for society.
Basically, this was my situation. But I paid off my student loans and I have some money in the bank now so I have some leverage as I shop around for my next job.
I felt that not only was I underused technically, but also that my contribution was a net negative for society.
In the light of such pretentious behaviour I have no idea why apple users have a reputation of being pragmatic and down2earth. </irony>
I wouldn't like to pay more than €500 on a smartphone. And ...,iP6 < €500 < iP7,...
Actually I am a happy Android user. But I don't like too much of my data in one basket. Which is why I would consider iPhone for my next phone.
But the praise of iOS regarding privacy is rather new. So my question aims at whether I could expect also the privacy for older iPhones or if this is only coming with newer versions.
Of course data safety is in this case a result of an Apple policy - which would affect all products - but possibly older iPhones still send too much data to Apple.
F.x. let's assume a Catalonian opposition politician who's investigated by the Spanish police and a judge decides his data should be searched. With this warrant they contact Apple. Would apple now send all their data about the guy to the police - how much do they have?
That's another question I ponder besides ad tracking policies.
For your spanish case, I would refer to the case of the US terrorists: Apple prefered to pay a fine to the US government rather than unlocking it.
[1] I think they've always had this kind of policy, for the record.
I would love if they came up with a smart solution that blocked all pixels, but didn't by default block substantive images. This is increasingly important as new email apps come out that offer consumers the ability to easily send emails with tracking pixels [1].
1: https://techcrunch.com/2017/08/18/rapportive-founders-new-st...
I can't see how defining 'substantive' images could ever work. The other issue is that email clickable links are often unique and tracked, so images are unfortunately only part of the problem here.
You can't? Seems pretty straight forward, so long as you remember first and foremost that 100% accuracy is completely unnecessary. The "load all images" option can still be there, so all that's needed is a solution that's good enough to suffice the majority of the time and shape norms and standard-case. That leaves lot of low hanging fruit. To start with are basic heuristics like that there is no need in email for 1x1 or 2x2 or 3x3 or whatever pixel images, or images where the pixels are entirely set to transparent. A lot of tracking stuff, particularly mass scale efforts tied to multiple parties beyond the sender, is pretty blatantly content free for even a totally dumb static rule set. Slightly more smarts could be used to discriminate based on simple sender trust heuristics, such as whether the email is cryptographically signed, they're in your contacts book, whether you've ever replied or clicked through, etc. Finally this could be another area where, just as they did here with cookies, Apple applied some basic ML to answer the "likely substantive" question. Again, remember that failing here doesn't necessarily matter because it can still be an improvement over the status quo.
And if we can eliminate a bunch of low-hanging fruit (e.g., from consumers who don't care enough about tracking to put a trackable company logo image in their signature), that's better than nothing.
Apple could probably use ML to try and guess ahead of time whether a URL is a tracking pixel, but they have to load at least some of them first to be able to figure that out.
See Superhuman. They're using tracking pixels with no related images or links.
Microsoft might, even though Bing is profitable and in 2015 brought in ~ $1b a quarter https://techcrunch.com/2015/10/22/bing-is-profitable/ . Might be too much money for Microsoft to ruin it.
All Apple right I think, but if they wanted to hurt Google they could start a search engine, maybe by buying DDG.
https://www.theverge.com/2017/6/1/15726778/chrome-ad-blocker...
By the way, a friendly reminder that EFF is happy to take donations and there are a variety of ways to do so.
> The Chrome ad blocker doesn’t just help publishers, it also helps Google maintain its dominance. And it advantages Google’s own ad units, which, it’s safe to say, will not be in violation of the bad ad rules.
Don’t be evil, indeed.
Get where, exactly? 88% of Google money comes from Ads[0], if you think their plan is to remove them from web you are either crazy or stupid.
[0] - http://www.businessinsider.de/how-google-apple-facebook-amaz...
[1] https://support.mozilla.org/en-US/kb/tracking-protection-pbm...
In what way is this bad? (Yes, I have third party cookies blocked. No, I'm not unblocking them.)
Do not track is snake oil anyway...
I did try this on iOS 11, which they probably don't have much data for yet and would explain some of the unique-ness, but you said iOS 10.3.3 which is much less new.
Maybe iPhone users just don't try panopticlick very much?
So the getComputedStyle() trick doesn't work anymore. Is that what your referring to?
Is this still possible? I was under the impression this is prevented in most browsers.
https://lcamtuf.blogspot.fr/2016/08/css-mix-blend-mode-is-ba...
Two years later, it was implemented, and the demo seems to be working here in Firefox 56: http://lcamtuf.coredump.cx/whack/
Looking at all the anti-Apple bile and conspiracy theory crap on this thread, it looks like the anti-Apple crowd are completely unhinged by it as well.
https://www.apple.com/hotnews/thoughts-on-flash/
i'd love to see such thing wrt the ad industry whinging like this. it would be so great.
But, it's still a proprietary system, and there are far fewer open source apps in the App Store compared to the Play store.
Maybe I'm better continuing as I do now -- Android, but with Firefox + blocking plugins installed.
I've always had an Android phone and an iPad so I've tended to choose applications that are cross platform so switching is easy for me. I think my next phone is going to be an iPhone because I'm starting to feel like a sharecropper on the Google farm.
If I have a third party reviews module - Feefo, BazaarVoice etc. - will that work?
Is this the end for 'AddThis' and other tracker things marketing type insist on bulking the page load times with?
I don't like any giant company saying, "trust us, our code is completely closed and we put up tons of road blocks for you unless you use it the way we say you should, but we take your privacy seriously. Trust us <EvilSmile />"
As long as Apple is a closed and secretive company, I won't consider them advocates for users.
If I were an ad network, I'd long ago switched to local storage and browser fingerprinting. Especially if it's my very survival as a business is at stake.
LocalStorage is just an icing on top to better cross-reference users in the scope of the same site.
So just compartmentalize. If there's some set of online activity that you don't want linked to you, do it in a dedicated VM. With Internet connectivity via some mix of VPNs and Tor. Everything that Mirimir does online is linked, at least somewhat. But that's fine, because it's not linked to my meatspace identity.
Point being that this "fight for the users" centered around 3rd party cookies is a privacy theatre. If 3rd party cookies were to be completely blocked on every single computer tomorrow, the ad industry will just switch to another option and nothing will change. But this does make Apple look like privacy champions.
Be aware of this - we all know advertising is abused, and has tired users - but it's tricky to find a vendor of hardware being the gate keeper of such stance.
Next step is main media groups start to block safari browsers.
Oh wow! I didn't realize that having my browsing habits picked through by corporations just to show me ads for products I already bought was such a huge honour. Thanks for this.
> Next step is main media groups start to block safari browsers.
That'll be awesome, I won't have to guess which sites respect my privacy since the ones that don't will just fail to load.
But giving all your information to Apple, is somehow, ok.
They know who you are, if you'll buy the next iphone, they target advertising at you through their own mediums... but that's fine.
> That'll be awesome, I won't have to guess which sites respect my privacy since the ones that don't will just fail to load.
Soon your world will be all Apple. Amen.
You complain about targeted advertising, but you don't complain about the walls that are being built around you - probably cause you can't see them since they're being built brick by brick.
There is no relevant communication from any advertiser to me. When I need something or want to know about things, I research it. Other information might come from friends and family. I do not care about what a to-me-unknown third party thinks a product is worth (including my attention), because their entire agenda is to bullshit me into buying something REGARDLESS of the need or quality of the product they talk about.
Be critic. Research is influenced by advertisers, that's why you have copy writers, SEO specialists, influencers, and millions of dollars supporting it.
Mate you're a sitting duck.
I might be an asshole who can be considered useless because I don't bring the ad industry a single cent, but I'm certainly not a sitting duck, mate.
Obviously, but that doesn't mean I want to make it easier for them to influence me by letting them track me and target ads specifically towards me.
¹It could theoretically be done, e.g. maybe the ad company provides 1000 possible ads and my device selects the best one itself. But I can't see anyone actually doing that.
Poor users, deprived of the joys of targeted advertising :(
But if giving all your biometrics data to Apple and limit yourself to their brand is the way to go - mate, you're using the right products. In a near future your world will be all-Apple, and you won't even notice.
Right now Apple _might_ be a dominant share in the SmartWatch category but certainly not in any other category they produce products in (phones, tv boxes, computers).
In a current future some people buy almost everything through Amazon, do all their socializing with Facebook, and do all their e-mailing and internet searching with google. All three of those comoanies track you as you go around the web and exploit every little bit of information they can to build expansive profiles about people in the world.
Apple doesn't track you around the web and is (and has, they stopped apps from tracking users in particular ways in the past) activitely making it harder for entities to follow you around the web.
Kudos to Apple.
That data is stored in your phone - when the FBI has to ask permission to Apple to have access to a phone, that phone doesn't belong to you - it belongs to Apple. They can blast through your door and get through everything you have - phone records, phones, laptops, photos, documents, even your bank account. But not your Apple smartphone - that's some fucked up shit going right there.
> Apple doesn't track you around the web and is (and has, they stopped apps from tracking users in particular ways in the past) actively making it harder for entities to follow you around the web.
Apple doesn't need to track you around the web - Apple knows who you are. They just don't want everyone else to know who you are - keep you locked up.
You can turn tracking on if you wish. I'd prefer to leave it off. What you seem to be advocating for is a world where no one can turn tracking off.
Those are still malpractices. I'm not claiming it's perfect - far from it - but I think it is useful in all the chaos.
No, I'm just stating that it shouldn't be up to Apple to decide it.
Yes, I would, for two reasons. First, the more poorly targeted the advertising is, the less effective it is at manipulating my mental state. As much as we'd all like to pretend to be Ubermenschs unaffected by advertising, we are not, and even the effort of consciously countering the subconscious impacts is one I'd rather not have to take.
Second, such poorly targeted ads would be accompanied by not being worth much as an ad; ultimately the ad system is fed by actual purchases in some sort of vague reaction to the ads, so poorly targeted ads would starve the incoming funds to the whole system, and be much more likely to be simple destroyed by lack of effect.
At this point, I see more relevant ads on broadcast television than on the internet.
Advertising is abused. End of story. People are starting to realize they can let it affect their life, or prefer products that respect it.
Someone is gonna have access at some point to that information, there is no way around it. You seem to be on the side of letting anybody get access to it. Others do not want that and think they can trust Apple to guard it. It's their choice, it is not the advertiser's. The worst that can happen is Apple fails to honor its promise, and then well be back where we started.
I don't know why, maybe you are part of the ad industry, maybe you just like to have no privacy, but your emotional appeal to a dark Apple-owned future full of zombies is cartoonish at best.
Would it be less tricky if it was an operating system vendor? If one of the Linux distros packages a default browser with this block would you say the same?
Yes, I think I would say the same. Same apply for Microsoft, with Edge.
The claim of privacy, might support isolation and that's how you start to build bubbles around people.
We should keep in sight what's the goal of targeted advertising - is to deliver relevant a message to the right users. It's heavily abused, indeed, and it should be revised.
But deprive the capacity of segmentation from a brand that know's everything about you - which Apple does - it's just not right imo.
This is completely backwards. Tracking is what allows Facebook et al. to build bubbles around people by "delivering relevant messages to the right users". Privacy is about users having control about what information companies collect about them and how that information is used. If I don't want companies to track my information (because I don't find targetting at all useful) I should be able to make that choice and ad companies should respect it. The fact that they "work around" tracking protections, as described in the article, is pretty despicable.
> I should be able to make that choice and ad companies should respect it
Exactly - you should make that choice, not Apple by default.
No, the goal is to make more money. Relevant is a sometimes side effect. The "right users" might also be the ones that are drunk, or emotionally vulnerable, or just got paid, or won at blackjack, or etc.
People are submitting all the biometric data.
This is a direct threat to their business models, and we all know desperate times call for desperate measures - specially on industries that work with thin margins already, and are getting pressured for high quality inventory.
Probably the next step is stop targeting safari browsers through programmatic buying, and if the inventory of safari browser users is worthless, publishers will act I think.
That would be an interesting development. I doubt it.
1. Methinks the advertisers doth complain too much. iOS devices have essentially no way to block advertising. Not in the browsers, not by configuring certain settings. Advertisers should count their lucky stars over this.
2. Don't assume altruism here. Apple is a gatekeeper of very valuable data for advertisers. Afaik they don't have an ad tech arm, but they're sitting on an inordinately large amount of strong signal. They could sell it, and sell advertisers into their own ecosystem.
Edit: I'm told by several commenters that I'm wrong. And I'm happy to be. I'd like to move my goalposts and say that native apps do not have those capabilities :)
As a customer really it seems they talk a lot about privacy yet implements "sneaky" changes like this, it seems a bit dishonest.
1. I know the feature is a different in IOS (it only disconnects connected devices) but for location services/tracking this is effectively the same as android. see: https://support.apple.com/en-us/HT208086
A privacy conscious user now has to do 4 actions (Unlock, open Settings, WiFi, disabling it) instead of two (swipe up, disabling it) to disable the WiFi.
I doubt many normal users would notice the difference, maybe thinking the toggle has the same functionality as before thus thinking they won’t constantly broadcast their known WiFi networks and thereby the pretty accurate location of their frequently visited places.
Please correct me if I misunderstood something!
Edit: I meant standard as in: If no other option than SMS 2FA is available.
I rarely go into Settings to disable WiFi, but it seems like I'll have to start doing that now.
Apple "does right by users". That's ok. But I'd wager this is only because that type of positioning is now Apple's chosen market differentiating* strategy. Against Google. Apple seems to want to position itself as the device that guarantees privacy and security. Apple would like to maintain exclusive access to a market segment that values security and privacy above all.
It worked for BlackBerry. Strong and almost cult-like loyalist following mostly guaranteed BB's reach in the executive circles. Even after BB became "Veblen", the device was in high demand. In such a market segment, the price per device doesn't really matter. My view is consistent with the apparent "horror" prices seen for the new iPhone.
If my guess is right, it's a shame about Apple's chosen direction. I love their products.
Apple isn't the problem here, Google and Facebook is.
Apple realised there is a market of privacy minded people who don't want to trade themselves to get a phone at a low price.
Apple can be privacy minded for profit and "do right by the users" at the same time. They aren't diametrically opposed to each other.
It is sad that we expect that a company trying to stay profitable is trying to screw users over in some way.
I'm not saying its not true in many cases, just in this case.
Because it's too easy when you see a company that once dominated this space with Jobs' legacy.
It's easy to be the good guy. It's morally reprehensible even to advertise yourself as such. Jobs' legacy of thinking differently has been recently misapplied with idiotic decisions like no headphone jacks, removal of fn keys, removal of magsafe power etc.
It would seem that the "innovation department" Apple would rather settle for difference BY DEFAULT.
That's the shame.
If that was the case others would be doing it too. For Google though it's extremely hard. And Microsoft caved to advertisers immediately.
>It's morally reprehensible even to advertise yourself as such
I don't see anything morally reprehensible to advertise yourself as such -- assuming you indeed are such.
At worst it can be a little tacky -- and that's for people. Companies are not people, and they do have to advertise their good qualities and what they offer that their competitors don't. Which is what Apple does.
>It would seem that the "innovation department" Apple would rather settle for difference BY DEFAULT.
Yeah, poor them. They only have the most exciting phone on the planet, with the best hardware (obliterating competitor cpus next and right) and a top-notch software platform.
Then why are Apple the only company even contemplating this?
And you have a problem with that because?
> Apple would like to maintain exclusive access to a market segment that values security and privacy above all.
Apple would like all the market. The fact they identified a currently underserved niche is just part of their game.
> In such a market segment, the price per device doesn't really matter. My view is consistent with the apparent "horror" prices seen for the new iPhone.
The cheapest iPhone is $350USD, and includes the same security and privacy focus as their most expensive device. Apple charges no premium for security.
Your problem should be with Google, Samsung, Facebook, and the Ad companies. That you are trying to shame Apple for recognizing the need for privacy and acting on it makes absolutely no sense.
What is wrong with positioning yourself as a device maker that guarantees privacy and security ? In the end it's a choice that they need to make and while it's definitely business driven, I don't see what they could possible do to make it less "shameful"?
There is a market for it and it's certainly something that I personally find very valuable. I don't like to be a "product" and rather pay a premium, although my iPhone SE is not that more expensive than a Pixel device for example.
The sweet spot for Android was when Google had the ~$400 Nexus line.
"...I love their products..."
Both sound fine by me.
You make it sound like Apple has some kid of unfair advantage over competitors. Or that Apple has monopoly power over the ideas of security and privacy. Bullshit.
> it's a shame about Apple's chosen direction.
I can't believe anyone could say that with a straight face.
The comment wasn't an obvious troll, it wasn't even borderline. In fact, I think it's rather presumptuous of you to assume the OP was insincere. That's your interpretation; that's you applying your own assumptions upon the mind of another person.
If you really cared about the quality of conversation, perhaps you should apply your morally superior tone towards the origin of this so-called flamebait and not one of the multitude of respondents?
Security and privacy should be a given. Security and privacy should never have been an easy opportunity for Apple to differentiate against its competitors.
Edit: Would I expect my wife to cook me a lovely welcoming dinner if I phoned her from work to tell her I had been an honest and loyal husband for the whole day? No.
(She would, had I had gotten her flowers without saying a word though! But that's another thing.)
I couldn't agree more. The news shouldn't be that Apple is doing something remarkable, it should be how other browsers fail to protect their users in similar ways.
Even so, that's a shame for the other vendors.
It's them who should "give it" to their users, to make it a given.
Apple has already done that.
>Would I expect my wife to cook me a lovely welcoming dinner if I phoned her from work to tell her I had been an honest and loyal husband for the whole day? No.
If you were the only honest husband around, then surely she would appreciate it.
I'm sorry, but blaming Apple in this case makes absolutely no sense to me, and I'm definitely not pro Apple usually. In this case, it's the rest of the world that is to blame for not caring about privacy and security as much as Apple/at all, not the other way around
No sir, I don't misunderstand your stupid argument.
The only way Apple's competitors are ever going to care about user privacy is if they're shamed into it through competition. If anything, Apple ought to beat this drum more loudly.
(Also, your husband analogy is junk. For your analogy fit properly, we'd need to live in a world where it was the norm for husbands to be routinely dishonest and disloyal. And the wife would need to be a product rather than another equal human.)