iPhone protected you from Facebook call scraping. Android, not so much
imore.com
imore.com
The first is the difference in business model, i.e. advertising versus whole-product.
The second is that Google starts with a permissive ecosystem mindset and locks stuff down as they go along; Apple starts with a conservative mindset and opens stuff up as they go along. Neither approach is inherently better than the other—the competing platforms are converging towards equilibrium—but Apple's approach does prove to have the upper hand when it comes to consumer privacy.
It's arguable that Google traded heavily on the relative freedom of the Android platform, and sucked in a lot of early adopter / tinkerer types on the promise of openness. Kind of ironic that for most people, most of the time, the open source nature of Android is now barely a historical footnote.
Certainly not for those tinkerer types. Often it's the tinkerer types who are concerned about privacy, and it's those types who install Copperhead OS or XPrivacy, which allows you to deny exactly this kind of thing. Not only that, but it'll let you block all those smaller ways of spying - like unique device IDs being phoned home to 6 different ad, analytics and crash handling services that the silly game you just installed uses.
It's hard for me to imagine using a phone on which I see ads, especially on YouTube, can't background apps like SSH clients, syncthing, even direct IMAP and SIP connections used to be a struggle for people on iOS (still may be?) or run app that Google/Apple have decided are evil piracy tools, like a manga reader or a torrent client manager and search tool. I have friends who even run emulators and use memory editors to cheat at mobile games regularly on their phones... very, very different models. Android is just a lot more flexible for a tinkerer to this day. All this is possible without exploits on most devices, allowed and accepted by many manufacturers.
There's this weird attitude on HN I see frequently where it seems like everything has to be "for the masses" for it to be of any value - tinkering by definition is not for the masses. Android devices probably shouldn't be for the masses, but for tinkerers, they really do pack a respectable punch in my opinion.
Hence why I said most.
But even then I think you're still massively overstating it. 6-10 years ago nearly everyone in my circle of geeky friends and colleagues had a root-kitted Android (Cyanogenmod or similar) or a jailbroken iPhone. Today that number is exactly zero.
I know many older people for whom an iPad is the first "computer" they've ever owned, and for them it's a lifeline to grandchildren and community. These are people who were never going to learn MacOS or Windows.
These people don't need your pity.
Plus - certainly 5-6 years ago - because of that whole product attitude, when you used an iPhone it simply felt a lot more polished than contemporary Android devices: I haven't really used Android enough recently to comment on whether or not that's still the case.
Also F-Droid got a nice look and functionality now, don't miss the Play store a bit.
In case someone does, there is the "yalp-app", google play backwards. It downloads apks from the play store with a fake account.
Not to mention the Android OS itself just being a data mining platform for Google's ecosystem of products.
I don't use Android myself, but I'm not going to say their approach doesn't have any upsides. For example, I still can't pick a third party iOS app to be my default email client.
A few highlights:
iPhone OS 2 — Native apps.
iPhone OS 3 — Apps can now connect to external accessories through serial I/O or bluetooth. Apple also began permitting turn-by-turn navigation and push notifications. Apps can now access music library. Lots of new APIs.
iOS 4 — Apps can now perform limited tasks in the background with multitasking. Lots of new APIs.
iOS 7 — Multitasking is liberated further. Apps can even send audio streams to other apps. Apps can also run JavaScript directly, allowing app scripting for the first time. Lots of new APIs.
iOS 8 — Developers can now create and sell third-party keyboards. Apps can now use Touch ID for authentication; have deeper access to camera exposure settings; register extensions for sharing and notification centre. Lots of new APIs.
iOS 10 — New APIs let VoIP apps do stuff that used to be exclusive to the native dialler. Some apps can now hook into Siri. Lots of new APIs.
More recently, Apple has relaxed its stance on apps executing (interpreted) code that is downloaded from the internet.
As far back as 2012 I used an Android CFW that sandboxed apps and returned empty values for whichever permissions were specified. And prior to that, it used 7.x at-will permissions. Since it was rooted, I could set the hosts file to block known malware domains and social media tracking anf load modules or patch issues instead of hoping it would be in a future update, if ever.
Until buying a Pixel (on Android 7.1.2-8.1), I'd never bothered with an OEM spin or stock builds, but it's been... okay. It's a shame it took half a decade for privacy options to catch up to the level of custom projects, and it's still primarily for device protection, but the situation isn't the sieve it once was with locked bootloaders and the over-broad support emphasis of earlier days.
Which is only useful for the consumers who have the skill, the depth of knowledge and who maintain that knowledge to keep it up-to-date. Maybe one percent of users. Probably fewer.
This is why most people outsource this stuff to third parties, just like we outsource the pasteurisation of milk and the maintenance of sewerage systems.
The typical analogy is the age-old argument about whether consumers should be expected to know how their car works. Maybe they should but that's beside the point—they don't. Insisting that they should is irrelevant. Most people don't know what brake fluid does and they won't care if you explain it to them.
And your example proves the point; because others cared to become the third-party, we have projects like LineageOS for smartphones and tablets. However, they could not have if Google had locked its OS down or restricted it to certain hardware.
Just because most people only want to know the time doesn't mean no one but clock makers should have the right to understand how clocks work.
Imagine a piece of software in the 2000s that sent all your emails, contacts, etc to a central server when running on your desktop computer, made by a large American company. There would have been utter outrage and legal ramifications.
There are a number of programs for power users on macOS that have stopped selling through the App Store or warn against limited functionality for apps bought through the store. There are also a lot of extremely useful apps for Android that work most effectively when your phone is rooted. Google's Safety Net has effectively made rooting a liability for all power users. When the OS provider is limiting what a user can do the device quickly devolves into an entertainment consumption device.
Bad actors should be treated as viruses and malware the same as they were before.
counterpoint: equifax
The same with the Facebook app (+ Android permissions, because even Facebook can't do full evil without Google apparently). And it's going to be the same result. Nothing is going to change, neither company will suffer much, nobody is going to jail. So his counterpoint is valid.
So the title made me think all Android are exposed to Facebook phone data scraping.
But considering how slow it is for Android devices to upgrade to the latest, it's probably still a sad state.
- The company [Facebook] reiterated that it wasn't saving the actual content of calls or SMS/MMS messages—something neither Ars Technica nor we claimed, but presumably other outlets did.
- It's actually a part of Facebook Lite and Messenger (and users can opt out [...] respectively). Facebook considers the data collection opt-in since the apps in question directly ask if you'd like to upload that information during setup.
[1] https://www.androidpolice.com/2018/03/25/facebook-gathering-...
App store validation == trusting Apple.
Because this was impossible without forcing users to stop using Objective-C. The language allows dynamic method dispatch and so it's always possible to allow internal API calls.
I don't think you're right; “entitlement” is a technical term used for OS-enforced permissions on Apple platforms.
I trust Apple a lot more than Google/Facebook/etc.
So I’m not sure why you posted that. Seems to undermine your argument.
I remember when I was an Android developer dealing with several issues relating to the fact that one carrier put a proxy in the networking stack.
Here is a recent example:
https://www.theregister.co.uk/2016/11/15/android_phoning_hom...
I've had this experience, and I still suspect it's likely to be confirmation bias. Chances are if you're speaking about something, there's a decent chance Facebook can figure out your likely interest in it in a variety of surprising and convoluted ways - your recent credit card purchases, news articles that may have mentioned it in passing, etc.
We also don't really notice all the times Facebook totally whifs a recommendation.